Getting Data In

Restoring specific source from frozen

splunkreal
Motivator

Hello guys,

we need to restore frozen data, however is it possible to choose which source to restore (not all sources), if yes, how?

Thanks.

* If this helps, please upvote or accept solution if it solved *
0 Karma

xpac
SplunkTrust
SplunkTrust

Hey,
when thawing (restoring) frozen data, you're limited to the name of the index, and the time range of the bucket(s) of that index you want to restore.
You can find details on how to do this in the "Restore archived indexed data" doc.

Hope that helps - if it does I'd be happy if you would upvote/accept this answer, so others could profit from it. 🙂

Get Updates on the Splunk Community!

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...