Installation

Merge indexes after restore fail

Greenwell01
New Member

Hi,

I recently had to re-install the os of the machine where splunk enterprise is hosted, I backed up my splunk server which included the index files. When the restore was done the every thing was restored except the index files. On starting the server, this caused all the indexes to be newly created but now only containing recent data.

Now I somehome need to merge the data from the backed up index to and index of the same name on the server.

I've tried renaming the backed up index, stopping splunk, copying it the index folder and restarting splunk. Splunk however does not recognise the new index and hence I cant query it.

Any ideas?

Thanks

Tags (1)
0 Karma

adonio
Ultra Champion

you are probably looking for thawing data or restoring data.
take a look at this link:
https://docs.splunk.com/Documentation/Splunk/7.1.3/Indexer/Restorearchiveddata
hope it helps

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...