Knowledge Management

Is there any other way to do a backup of KV store data than using the "splunk backup kvstore" command?

svendby90
Path Finder

We have an instance where KV store is not running and we're looking to clean the whole thing out. However, we would like to see if we're able to keep the data.

So, my question is; is there any other way to do a backup of KV store data than using the "splunk backup kvstore" command?

Labels (1)
0 Karma
1 Solution

tshah-splunk
Splunk Employee
Splunk Employee

Hey @svendby90,

There is an alternate way as well to take a backup of the kvstore other than the backup command. Steps are as below:

  • Stop splunk

 

$SPLUNK_HOME/bin/splunk stop​

 

  • Create tar of the kvstore directory

 

tar -cvzf <destination_path>/backup.tgz $SPLUNK_HOME/var/lib/splunk/kvstore​

 

  • Start splunk again

 

$SPLUNK_HOME/bin/splunk start​

 

---
If you find the answer helpful, an upvote/karma is appreciated

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

here is one old discussion how you could do it online without service break https://community.splunk.com/t5/Splunk-Enterprise/Are-there-any-automated-scripts-to-back-up-the-kvs...

r. Ismo

0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @svendby90,

There is an alternate way as well to take a backup of the kvstore other than the backup command. Steps are as below:

  • Stop splunk

 

$SPLUNK_HOME/bin/splunk stop​

 

  • Create tar of the kvstore directory

 

tar -cvzf <destination_path>/backup.tgz $SPLUNK_HOME/var/lib/splunk/kvstore​

 

  • Start splunk again

 

$SPLUNK_HOME/bin/splunk start​

 

---
If you find the answer helpful, an upvote/karma is appreciated

haraksin
Path Finder

How do you restore from this method? If I clean the KVstore after backing up like this, won't untarring over the cleaned files just put the system back in the state it was, uncleaned? Or even worse, would it break mongo?

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...