Splunk Enterprise

Restoring from db_ and rb_*

cybersecnutant
Explorer

Hello, unfortunately I am having to attempt to do a restore of copies of old db_* and rb_* structures that were basically rsync'd over time to some cold storage. I am noticing that things like ".bucketManifest" don't exist. I am trying to restore it to  a net new indexer cluster with the index configured in indexes.conf. I am happy to do this on a standalone indexer if that's the right way to do this, assuming that this is even possible.

 

To be clear, i have all of the directories that are prefixed with rb_* and db_*, but nothing else.

*EDIT* I actually only have db_*/rawdata/journal.gz
and rb_*/rawdata/journal.gz

Thanks

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

This should help you https://community.splunk.com/t5/Getting-Data-In/How-to-restore-frozen-archived-data-multiple-buckets...

If/when you are restoring this to single node, then is't enough that you restore only db_ or rb_ bucket not both as those contains same raw data. Restoring both just use unneeded space and give you some warnings when you start splunk.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...