Greetz,
So I have tried:
in a 4.2.3 instance but a whole lot of XML goes flying by and nothing seems to happen.
Looking at index health I see many thawed buckets but with an event count of 0!
I did manage to rebuild the 4.2 buckets. This instance was upgraded from 4.7.1 hence the bucket mix.
Please help!!!
Me being stupid as usual.
This was not so clear to me.
You have to uncompress ALL of the *.gz files in the bucket and rawdata/.
I thought that if the bucket itself was compressed what this instruction was alluding to.
http://docs.splunk.com/Documentation/Splunk/latest/admin/Restorearchiveddata#Thaw_a_pre-4.2_archive
2. If the bucket was compressed when originally archived, uncompress the contents in the thawed directory.
Me being stupid as usual.
This was not so clear to me.
You have to uncompress ALL of the *.gz files in the bucket and rawdata/.
I thought that if the bucket itself was compressed what this instruction was alluding to.
http://docs.splunk.com/Documentation/Splunk/latest/admin/Restorearchiveddata#Thaw_a_pre-4.2_archive
2. If the bucket was compressed when originally archived, uncompress the contents in the thawed directory.