Getting Data In

When should I restore from backup?

pdevlin
Explorer

What events should I be watching for in my Splunk logs? Does anyone have a list of specific error codes that would indicate the need to restore an index?

Tags (3)

gkanapathy
Splunk Employee
Splunk Employee

I guess I'm not sure why you want to restore an index from backup. It's an extremely abnormal condition, and I suppose that many things that went wrong could cause it, but if it did, someone is going to see something go wrong in the application, not the log.

pdevlin
Explorer

Index corruption, disk errors or VM/OS failures that cause file corruption, etc. I'd like to monitor Splunk logs for those specific errors that indicate an index is corrupt and/or not usable. Yes we would notice in the application that something is wrong but knowing the exact errors which indicate a corrupt index is vital for basic maintenance and support. Do you know if there is a complete list of Splunk error codes and what they mean?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...