Splunk Enterprise Security

Log restoration process

Rbsplunk95
New Member

Hello everyone, I am facing some issues with log restoration process from azure cloud to splunk . I have gone through the epoch time conversion process to get the exact date for file. then restore the particular file using the shell commands.

But right now I want to restore two months of log data in splunk. so the previous process is really time taking and there is a chance that we might miss some of the data for a particular time interval.

So is there any way we can restore the two months of date using some prebuild commands or is there any process to ease the task.

Thanks in advance. 

Labels (1)
0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

Hi,

I'm not sure if this is what you're asking about, but there's a doc on restoring based on internal audit logs: 

https://docs.splunk.com/Documentation/ES/6.4.0/Install/InstallEnterpriseSecuritySHC#Restore_incident...

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...