Getting Data In

Restore clustered frozen buckets to non-clustered instance

splunkreal
Motivator

Hello guys,

could you let me know how to properly restore frozen buckets from clustered indexers to non-clustered instance (VM)?

Thanks for your help 🙂

* If this helps, please upvote or accept solution 🙂 *
Labels (1)
0 Karma

maxywalker1
Explorer

Looking at having to do this to, just one bucket but over multiple years. As it is from a clustered index to a non-clustered, does this mean we only have to copy the data from one of the clustered indexes to the non-clustered one, or does the data need to come from all of the clustered indexes?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Haven't try this by myself, but you could try next.
If you have your test/dev-instance please try it or even download trial version and use it.

As bucket names in single node indexer vs. cluster are different you may need to rename that bucket from cluster mode to single node mode. But in test instance you could try it first with cluster named version. If it works and don't crash your instance use it and if not then rename that bucket to single node version and try again.
r. Ismo
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Restore the frozen buckets to the VM

Rebuild the index

 

splunk rebuild /full/path/to/bucket

 

Restart the indexer

---
If this reply helps you, Karma would be appreciated.

splunkreal
Motivator

Thanks, we may need to restore just a single day and just few sources, unfortunately in this case many buckets have large timeframe (several months), is there a solution to filter or we need to restore all of them?

* If this helps, please upvote or accept solution 🙂 *
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

You need to do restore a bucket base (min one whole bucket).

You could prepare that for the next time to update index.conf so that individual buckets are not for so long time.

r. Ismo

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...