Splunk Cloud Platform

How we can transfer or back up data to an AWS S3 bucket for the specified existing index?

Rakzskull
Path Finder

We have an index named ABC with a searchable retention period of 180 days and an archival period of 3 years. I would like to transfer all logs to AWS S3, as they are currently stored in Splunk Archive storage. Could you please advise on how to accomplish this?

Additionally, will this process include moving both searchable logs and archived logs to S3?

I would appreciate a step-by-step guide. If anyone has knowledge of this process, I would be grateful for your assistance. Thank you.

Labels (2)
Tags (1)
0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@Rakzskull 

Splunk manages the archival storage in DDAA, and you don’t have direct access to the underlying S3 buckets.

To export archived data:

  • Open a support ticket with Splunk.
Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

tscroggins
Influencer

Hi @Rakzskull,

Splunk support can assist with migrations from DDAA (Splunk-provided S3) to DDSS (customer-provided S3).

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...