Splunk Enterprise

Error on restoration of DDSS S3 bucket to Splunk Enterprise

MuhammadMurad
Explorer

Hello Everyone, 

We are trying to restore the DDSS data stored in S3 bucket to our Splunk Enterprise. We follow the step


https://docs.splunk.com/Documentation/SplunkCloud/9.0.2303/Admin/DataSelfStorage?_gl=1*gl0ykt*_ga*MT...

But we facing error like below?

MuhammadMurad_0-1706198189398.png

Any thought what might be the root cause? We did upload the data in the instructed directory but when rebuilding. we keep facing this error. 

Labels (1)
0 Karma
1 Solution

MuhammadMurad
Explorer

The issue resolve by manually create the index which we think its automatically created based on command in the documentation. So need to create manually the index and then run the rebuild command again, if facing this similar error message. 

View solution in original post

MuhammadMurad
Explorer

The issue resolve by manually create the index which we think its automatically created based on command in the documentation. So need to create manually the index and then run the rebuild command again, if facing this similar error message. 

scelikok
SplunkTrust
SplunkTrust

Hi @MuhammadMurad,

I noticed you missed $ before '$SPLUNK_HOME', please try using $SPLUNK_HOME

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

MuhammadMurad
Explorer

Thanks for the reply. actually we did that. above just example to show the error message

0 Karma

mattymo
Splunk Employee
Splunk Employee

Maybe try and check that you define `$SPLUNK_HOME` environment variable correctly or just point it to the absolute path? Doest like your "bucket path"

- MattyMo
0 Karma

MuhammadMurad
Explorer

We did basically. /opt/Splunk/...

Above screenshot just want to show  the error message

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...