Installation

Merge indexes after restore fail

Greenwell01
New Member

Hi,

I recently had to re-install the os of the machine where splunk enterprise is hosted, I backed up my splunk server which included the index files. When the restore was done the every thing was restored except the index files. On starting the server, this caused all the indexes to be newly created but now only containing recent data.

Now I somehome need to merge the data from the backed up index to and index of the same name on the server.

I've tried renaming the backed up index, stopping splunk, copying it the index folder and restarting splunk. Splunk however does not recognise the new index and hence I cant query it.

Any ideas?

Thanks

Tags (1)
0 Karma

adonio
Ultra Champion

you are probably looking for thawing data or restoring data.
take a look at this link:
https://docs.splunk.com/Documentation/Splunk/7.1.3/Indexer/Restorearchiveddata
hope it helps

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...