Getting Data In

Restore Data Question

hartfoml
Motivator

I have this retention settings like this

[firewall]

maxHotBuckets = 3
frozenTimePeriodInSecs = 48211200
maxTotalDataSizeMB = 1000000

I found out that the buckets were timed by the size and not the date.

I changed the maxTotalDataSizeMB and restored the old buckets to a restore directory.

I CP -rp the old buckets to the production firewall/db directory but I am not seeing the logs in the UI.

Do I need to restore to the "colddb" or "thaweddb"?

Can I just copy the buckets back into the production db?

Do I have to restart splunkd to read the data in the buckets?

Tags (2)
0 Karma
1 Solution

hartfoml
Motivator

So the above answer is for archived data. that is archived by splunk.

In my case I do a full back of the index files every month. Thanks to support guru "Joshua Backing" I found out that if you restore live buckets from tape and the bucket ID dose not conflict with any other live bucket you can just copy the bucket back to the /indexname/db directory then stop and start splunkd and whala the data is viable.

I did notice that many of the buckets moved to the /indexname/colddb right away. Again thanks to Joshua, he said this could be for normal more than 300 warm bucket rotation. the data is still searchable and will not be rotated out of the database until the size or time policy is reached.

Thanks again Joshua Splunk Support Rules

View solution in original post

0 Karma

hartfoml
Motivator

So the above answer is for archived data. that is archived by splunk.

In my case I do a full back of the index files every month. Thanks to support guru "Joshua Backing" I found out that if you restore live buckets from tape and the bucket ID dose not conflict with any other live bucket you can just copy the bucket back to the /indexname/db directory then stop and start splunkd and whala the data is viable.

I did notice that many of the buckets moved to the /indexname/colddb right away. Again thanks to Joshua, he said this could be for normal more than 300 warm bucket rotation. the data is still searchable and will not be rotated out of the database until the size or time policy is reached.

Thanks again Joshua Splunk Support Rules

0 Karma

kristian_kolb
Ultra Champion

just make sure that you increase the retention time/index size limits of the index before you copy the buckets back, otherwise the bucket will be dropped once again...

0 Karma

kristian_kolb
Ultra Champion

Here is the step-by-step instruction for how to restore archived (i.e. frozen) data;

http://docs.splunk.com/Documentation/Splunk/6.0/Indexer/Restorearchiveddata

/k

0 Karma

lukejadamec
Super Champion

In addition to that, you don't need to restart splunk when you move functional buckets to a production db, because splunk will automatically update the manifest over time. If you want the data immediately, then a restart will do that.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...