Getting Data In

Restore clustered frozen buckets to non-clustered instance

splunkreal
Motivator

Hello guys,

could you let me know how to properly restore frozen buckets from clustered indexers to non-clustered instance (VM)?

Thanks for your help 🙂

* If this helps, please upvote or accept solution if it solved *
Labels (1)
0 Karma

maxywalker1
Explorer

Looking at having to do this to, just one bucket but over multiple years. As it is from a clustered index to a non-clustered, does this mean we only have to copy the data from one of the clustered indexes to the non-clustered one, or does the data need to come from all of the clustered indexes?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Haven't try this by myself, but you could try next.
If you have your test/dev-instance please try it or even download trial version and use it.

As bucket names in single node indexer vs. cluster are different you may need to rename that bucket from cluster mode to single node mode. But in test instance you could try it first with cluster named version. If it works and don't crash your instance use it and if not then rename that bucket to single node version and try again.
r. Ismo
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Restore the frozen buckets to the VM

Rebuild the index

 

splunk rebuild /full/path/to/bucket

 

Restart the indexer

---
If this reply helps you, Karma would be appreciated.

splunkreal
Motivator

Thanks, we may need to restore just a single day and just few sources, unfortunately in this case many buckets have large timeframe (several months), is there a solution to filter or we need to restore all of them?

* If this helps, please upvote or accept solution if it solved *
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

You need to do restore a bucket base (min one whole bucket).

You could prepare that for the next time to update index.conf so that individual buckets are not for so long time.

r. Ismo

Get Updates on the Splunk Community!

New This Month - Splunk Observability updates and improvements for faster ...

What’s New? This month, we’re delivering several enhancements across Splunk Observability Cloud for faster and ...

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...