Hello guys,
could you let me know how to properly restore frozen buckets from clustered indexers to non-clustered instance (VM)?
Thanks for your help 🙂
Looking at having to do this to, just one bucket but over multiple years. As it is from a clustered index to a non-clustered, does this mean we only have to copy the data from one of the clustered indexes to the non-clustered one, or does the data need to come from all of the clustered indexes?
Restore the frozen buckets to the VM
Rebuild the index
splunk rebuild /full/path/to/bucket
Restart the indexer
Thanks, we may need to restore just a single day and just few sources, unfortunately in this case many buckets have large timeframe (several months), is there a solution to filter or we need to restore all of them?
Hi
You need to do restore a bucket base (min one whole bucket).
You could prepare that for the next time to update index.conf so that individual buckets are not for so long time.
r. Ismo