Splunk Enterprise

Error on restoration of DDSS S3 bucket to Splunk Enterprise

MuhammadMurad
Explorer

Hello Everyone, 

We are trying to restore the DDSS data stored in S3 bucket to our Splunk Enterprise. We follow the step


https://docs.splunk.com/Documentation/SplunkCloud/9.0.2303/Admin/DataSelfStorage?_gl=1*gl0ykt*_ga*MT...

But we facing error like below?

MuhammadMurad_0-1706198189398.png

Any thought what might be the root cause? We did upload the data in the instructed directory but when rebuilding. we keep facing this error. 

Labels (1)
0 Karma
1 Solution

MuhammadMurad
Explorer

The issue resolve by manually create the index which we think its automatically created based on command in the documentation. So need to create manually the index and then run the rebuild command again, if facing this similar error message. 

View solution in original post

MuhammadMurad
Explorer

The issue resolve by manually create the index which we think its automatically created based on command in the documentation. So need to create manually the index and then run the rebuild command again, if facing this similar error message. 

scelikok
SplunkTrust
SplunkTrust

Hi @MuhammadMurad,

I noticed you missed $ before '$SPLUNK_HOME', please try using $SPLUNK_HOME

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

MuhammadMurad
Explorer

Thanks for the reply. actually we did that. above just example to show the error message

0 Karma

mattymo
Splunk Employee
Splunk Employee

Maybe try and check that you define `$SPLUNK_HOME` environment variable correctly or just point it to the absolute path? Doest like your "bucket path"

- MattyMo
0 Karma

MuhammadMurad
Explorer

We did basically. /opt/Splunk/...

Above screenshot just want to show  the error message

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...