Splunk Enterprise

Are there any automated scripts to back up the kvstore on each Splunk server as part of a basic back? Daily or weekly?

SamHTexas
Builder

Are there any automated scripts to back up the kvstore on each Splunk server as part of a basic back? How often should I backup the Kvstores?

Also what do I need to backup in Splunk Enterprise Security please.

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

We are using this https://splunkbase.splunk.com/app/5328/. Of course you can use that splunk backup kvstore from command line, but then you must add user + password somewhere in plain text, which is something that I don't like.

How often you should run this? That depends on how active your kvstore is and how long RPO is.

r. Ismo

SamHTexas
Builder

Sir, which servers do have KVstores that are worth backing up using this tool & how often do I back the KVstores on the Splunk servers? Thank u in advance.

Tags (1)
0 Karma

ragedsparrow
Contributor

This isn't really a question that anyone can answer for you.  This is basically something that you need to answer yourself.  I'd base the frequency based on how much data in the kvstore(s) you can lose in the instance of a failure, as well as the storage that you're willing to use for backups.

0 Karma

SamHTexas
Builder

Thank u for your message. I know KVstores are specific for Ent. Security app. but are there other KVstores on other Splunk servers worth backing up ? Which ones please. Thank u sir.

Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
You must backup at least your SHC nodes. And also I propose to backup other SH nodes too.
Of course if you have kvstore in use on other nodes also, you should backup those too.

SamHTexas
Builder
Spoiler
Thank u sir as always for your expert help. One more question. Should I be installing the app # 5328 on each server individually to back up the KVstores please? Thank u
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Yes you should.
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...