Hi, (My Splunk Apps are installed on Linux Servers)
I would like to restore logs from frozen data and read them
So please I need the steps to do it.
Copy the directory from frozen directory to thaweddb. Then run the below command
splunk rebuild [path to thawed bucket]
e.g. splunk rebuilt \opt\splunk\var\lib\splunk\defaultdb\thaweddb\db_1181756465_1162600547_1001
Restart the indexer
https://docs.splunk.com/Documentation/Splunk/8.1.1/Indexer/Restorearchiveddata#.2Anix_users
Copy the directory from frozen directory to thaweddb. Then run the below command
splunk rebuild [path to thawed bucket]
e.g. splunk rebuilt \opt\splunk\var\lib\splunk\defaultdb\thaweddb\db_1181756465_1162600547_1001
Restart the indexer
https://docs.splunk.com/Documentation/Splunk/8.1.1/Indexer/Restorearchiveddata#.2Anix_users