Getting Data In

How to restore logs from frozen bucket?

vnguyen46
Contributor

Hi - in frozen\index\colddb, I have the following files (db_ and rb_)
[splunk@spkpnxl1 wineventlog]$ cd colddb
[splunk@spkpnxl1 colddb]$ ls
db_1564149292_1564145928_6839_1741185A-25EA-4E95-9BBD-447DB7D77D6E
rb_1564419759_1564416947_13512_E3EF5E9B-B5C5-4352-B9DA-61B24C683D2B

How can I restore/re-thaw these files?
Thanks,

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Copy the bucket(s) into the appropriate thaweddb directory, as specified in indexes.conf. Then run the splunk rebuild command on the indexer. You don't need to worry about the rb_* buckets as they're replicates of buckets stored elsewhere.
See https://docs.splunk.com/Documentation/Splunk/7.3.1/Indexer/Restorearchiveddata#Thaw_a_4.2.2B_archive for details.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Copy the bucket(s) into the appropriate thaweddb directory, as specified in indexes.conf. Then run the splunk rebuild command on the indexer. You don't need to worry about the rb_* buckets as they're replicates of buckets stored elsewhere.
See https://docs.splunk.com/Documentation/Splunk/7.3.1/Indexer/Restorearchiveddata#Thaw_a_4.2.2B_archive for details.

---
If this reply helps you, Karma would be appreciated.

kvm
Explorer

@richgalloway how do I run the rebuild command for multiple files?

I'm trying to rebuild the logs for 3 months, and I have hundreds of files, instead of running the rebuild command for each file one by one, is there any other way to run bulk? maybe wildcard or something?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Write a script to rebuild the files.

---
If this reply helps you, Karma would be appreciated.

vnguyen46
Contributor

Thank you so much. In the indexes.conf file, I have:
[wineventlog]
homePath = volume:primary/wineventlog/db
coldPath = volume:cold/wineventlog/colddb
thawedPath = $SPLUNK_DB/wineventlog/thaweddb
frozenTimePeriodInSecs = 5768000 (~67 days)
For some reasons, I don't see any files in the colddb folder older than 45 days. Do you know what caused the issue and what I need to do if I need to keep the log for 180 days?

Thank you,

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This should be a separate question.
Once Splunk freezes a bucket it no longer will do anything with it. It's up to you to manage the frozen buckets so they remain available for the desired time.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnguyen46
Contributor

Thank you.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...