Getting Data In

Restoring specific source from frozen

splunkreal
Motivator

Hello guys,

we need to restore frozen data, however is it possible to choose which source to restore (not all sources), if yes, how?

Thanks.

* If this helps, please upvote or accept solution if it solved *
0 Karma

xpac
SplunkTrust
SplunkTrust

Hey,
when thawing (restoring) frozen data, you're limited to the name of the index, and the time range of the bucket(s) of that index you want to restore.
You can find details on how to do this in the "Restore archived indexed data" doc.

Hope that helps - if it does I'd be happy if you would upvote/accept this answer, so others could profit from it. 🙂

Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...