Getting Data In

When should I restore from backup?

pdevlin
Explorer

What events should I be watching for in my Splunk logs? Does anyone have a list of specific error codes that would indicate the need to restore an index?

Tags (3)

gkanapathy
Splunk Employee
Splunk Employee

I guess I'm not sure why you want to restore an index from backup. It's an extremely abnormal condition, and I suppose that many things that went wrong could cause it, but if it did, someone is going to see something go wrong in the application, not the log.

pdevlin
Explorer

Index corruption, disk errors or VM/OS failures that cause file corruption, etc. I'd like to monitor Splunk logs for those specific errors that indicate an index is corrupt and/or not usable. Yes we would notice in the application that something is wrong but knowing the exact errors which indicate a corrupt index is vital for basic maintenance and support. Do you know if there is a complete list of Splunk error codes and what they mean?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...