Getting Data In

Reindex old data from zip files

oliverw
New Member

I am trying to recover log data that has aged out of the Splunk index.
I have access to the original log files, they have been individually zipped, one log file per zip file. When our archive script did this originally, Splunk was smart enough to not re-index them. Now I want to re-index them as new files.

I have created a new recovery directory, added a new monitor to inputs.conf, and set crcSalt

[monitor://D:\IISLogs\LogFiles\Recovery]
disabled = 0
crcSalt = <SOURCE>
index = ms_iis
sourcetype = ms:iis:default

This all works fine with new test file, even a zip file, but when I copy one of the old zipped log files, they are not indexed.
If I unzip the log file, it is indexed correctly.
I have a lot of logs to ingest. How can I get Splunk to re-index them without unzipping them?

Tags (3)
0 Karma

p_gurav
Champion

Instead of reindexing can you try restoring archive data. Refer below document:
http://docs.splunk.com/Documentation/Splunk/7.0.2/Indexer/Restorearchiveddata

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...