Installation

Merge indexes after restore fail

Greenwell01
New Member

Hi,

I recently had to re-install the os of the machine where splunk enterprise is hosted, I backed up my splunk server which included the index files. When the restore was done the every thing was restored except the index files. On starting the server, this caused all the indexes to be newly created but now only containing recent data.

Now I somehome need to merge the data from the backed up index to and index of the same name on the server.

I've tried renaming the backed up index, stopping splunk, copying it the index folder and restarting splunk. Splunk however does not recognise the new index and hence I cant query it.

Any ideas?

Thanks

Tags (1)
0 Karma

adonio
Ultra Champion

you are probably looking for thawing data or restoring data.
take a look at this link:
https://docs.splunk.com/Documentation/Splunk/7.1.3/Indexer/Restorearchiveddata
hope it helps

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...