Splunk Enterprise

Error on restoration of DDSS S3 bucket to Splunk Enterprise

MuhammadMurad
Explorer

Hello Everyone, 

We are trying to restore the DDSS data stored in S3 bucket to our Splunk Enterprise. We follow the step


https://docs.splunk.com/Documentation/SplunkCloud/9.0.2303/Admin/DataSelfStorage?_gl=1*gl0ykt*_ga*MT...

But we facing error like below?

MuhammadMurad_0-1706198189398.png

Any thought what might be the root cause? We did upload the data in the instructed directory but when rebuilding. we keep facing this error. 

Labels (1)
0 Karma
1 Solution

MuhammadMurad
Explorer

The issue resolve by manually create the index which we think its automatically created based on command in the documentation. So need to create manually the index and then run the rebuild command again, if facing this similar error message. 

View solution in original post

MuhammadMurad
Explorer

The issue resolve by manually create the index which we think its automatically created based on command in the documentation. So need to create manually the index and then run the rebuild command again, if facing this similar error message. 

scelikok
SplunkTrust
SplunkTrust

Hi @MuhammadMurad,

I noticed you missed $ before '$SPLUNK_HOME', please try using $SPLUNK_HOME

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

MuhammadMurad
Explorer

Thanks for the reply. actually we did that. above just example to show the error message

0 Karma

mattymo
Splunk Employee
Splunk Employee

Maybe try and check that you define `$SPLUNK_HOME` environment variable correctly or just point it to the absolute path? Doest like your "bucket path"

- MattyMo
0 Karma

MuhammadMurad
Explorer

We did basically. /opt/Splunk/...

Above screenshot just want to show  the error message

0 Karma
Get Updates on the Splunk Community!

New Case Study Shows the Value of Partnering with Splunk Academic Alliance

The University of Nevada, Las Vegas (UNLV) is another premier research institution helping to shape the next ...

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...