Getting Data In

What are good backup strategies for indexer buckets?

pdoconnell
Path Finder

What strategies do people use for backups of their buckets? Is there a clean way to identify "new" buckets for a given day based on their file name?

0 Karma

ChrisG
Splunk Employee
Splunk Employee

The documentation recommends doing incremental backups of warm buckets, see Back up indexed data in the Managing Indexers and Clusters of Indexers manual. As skalliger mentions in his answer, the bucket names do indicate the age of the data they contain.

0 Karma

skalliger
Motivator

Splunk recommends snapshot technology to backup buckets. Due to hot buckets being written to, you should consider not backing them up via snapshots, as you may miss data. Apart from that, snapshotting all the other buckets is recommended (warm, cold, ...).

Every bucket follows a naming convention with two timestamps (newest and oldest time):
http://docs.splunk.com/Documentation/Splunk/6.5.1/Indexer/HowSplunkstoresindexes#Bucket_naming_conve...

Did that answer your question?

Skalli

0 Karma

anand_singh17
Path Finder

Snapshot makes you get you data backed up for your instant point of time data. So very reason, Splunk recommends to have resiliency to be maintained, in case to protect data

0 Karma

ddrillic
Ultra Champion

If you have an Hadoop cluster, you might consider Hunk for a full backup solution - Is there a solution to back up Splunk data into HDFS to make it available for search via Hunk?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...