Splunk Cloud Platform

Federated Search Archived Data in s3?

pdominicb
New Member

Is federated search able to search frozen buckets in s3? Or only raw logs?

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk is unable to search frozen buckets in any location.  Frozen buckets must be thawed before they can be searched.

As I understand it, FS-S3 is intended to allow searching of raw data resident in an S3 bucket.  It's not for searching "cooked" data.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...