Splunk Cloud Platform

Federated Search Archived Data in s3?

pdominicb
New Member

Is federated search able to search frozen buckets in s3? Or only raw logs?

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk is unable to search frozen buckets in any location.  Frozen buckets must be thawed before they can be searched.

As I understand it, FS-S3 is intended to allow searching of raw data resident in an S3 bucket.  It's not for searching "cooked" data.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...