Getting Data In

Steps to restor Frozen Data

saeed
Explorer

Hi, (My Splunk Apps are installed on Linux Servers)

I would like to restore logs from frozen data and read them

So please I need the steps to do it.

Labels (1)
0 Karma
1 Solution

saravanan90
Contributor

Copy the directory from frozen directory to thaweddb. Then run the below command

splunk rebuild [path to thawed bucket] 

e.g. splunk rebuilt \opt\splunk\var\lib\splunk\defaultdb\thaweddb\db_1181756465_1162600547_1001

Restart the indexer

https://docs.splunk.com/Documentation/Splunk/8.1.1/Indexer/Restorearchiveddata#.2Anix_users

View solution in original post

saravanan90
Contributor

Copy the directory from frozen directory to thaweddb. Then run the below command

splunk rebuild [path to thawed bucket] 

e.g. splunk rebuilt \opt\splunk\var\lib\splunk\defaultdb\thaweddb\db_1181756465_1162600547_1001

Restart the indexer

https://docs.splunk.com/Documentation/Splunk/8.1.1/Indexer/Restorearchiveddata#.2Anix_users

saeed
Explorer

Thanks a lot

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Community Content Calendar, October Edition

Welcome to the October edition of our Community Spotlight! The Splunk Community is a treasure trove of ...