Is it possible to archive frozendbs to tape and pull that data back for splunk to read at a later date?
For example, I'd like to do something like this.
All data has to be retained for 3 years.
Warm / Hot Dbs = 3 months
frozendb = 1 year
Frozendb is backed up to tape once per year.
You can copy frozendb to any location that you like. Just make sure you can pull the data out of it when you need it.
How could we restore that data? If we had to pull a tape back from 2 years ago could I point a new index at the frozendb folder from 2 years ago and run queries?
You have to manually copy the data to the thawedb directory. The thaw directory is configured in indexes.conf. Please refer to the documentation as the process is a bit more involved than that:
http://docs.splunk.com/Documentation/Splunk/6.3.0/Indexer/Restorearchiveddata