Getting Data In

Reindex old data from zip files

oliverw
New Member

I am trying to recover log data that has aged out of the Splunk index.
I have access to the original log files, they have been individually zipped, one log file per zip file. When our archive script did this originally, Splunk was smart enough to not re-index them. Now I want to re-index them as new files.

I have created a new recovery directory, added a new monitor to inputs.conf, and set crcSalt

[monitor://D:\IISLogs\LogFiles\Recovery]
disabled = 0
crcSalt = <SOURCE>
index = ms_iis
sourcetype = ms:iis:default

This all works fine with new test file, even a zip file, but when I copy one of the old zipped log files, they are not indexed.
If I unzip the log file, it is indexed correctly.
I have a lot of logs to ingest. How can I get Splunk to re-index them without unzipping them?

Tags (3)
0 Karma

p_gurav
Champion

Instead of reindexing can you try restoring archive data. Refer below document:
http://docs.splunk.com/Documentation/Splunk/7.0.2/Indexer/Restorearchiveddata

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Improve Delivery Assurance with S2S ACK for Edge Processor

Edge Processor helps Splunk customers process data closer to the source: filtering, transforming, masking, and ...

.conf26 Platform Sessions: Turn Machine Data into Agentic Action

As autonomous agents and multi-cloud architectures reshape modern IT, data platforms have to do far more than ...

Introducing the Launch of Edge Processor in Hybrid Mode!

Modernize Data Ingestion Without Starting Over  For years, organizations have relied on Splunk's proven ...