Splunk Enterprise

Splunk backup and restore

kevbot
Engager

Hello,

I've read the following documentation:

https://docs.splunk.com/Documentation/Splunk/9.2.0/Indexer/Backupindexeddata

https://docs.splunk.com/Documentation/Splunk/9.2.0/Admin/Backupconfigurations

Basically to back up Splunk, I need to make a copy of "$SPLUNK_HOME/etc/*" and "$SPLUNK_HOME/var/lib/splunk/defaultdb/db/*" (after rotating the hot buckets.)

My question is, how is this restored? Would I just paste the copied files back in to a working Splunk instance? Then the data can be searched normally?

Thank you

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

rule of thumbs. Never restore anything into running system unless your product support it!

If you have single instance where you have take that backup, then you should use separate dummy/empty instance where to restore it. I suppose that even that case you will have some issues with files e.g. hot buckets and buckets which has switch state from warm to cold or cold to frozen during your backup time. If you have used e.g. snapshot for backup then this is not so big issue. After restoration just switch this service up (change splunk node name or shutdown the primary instance first).

If you have clustered environment then it’s much harder to get working backup and restore it. I really suggest that you use snapshots for backing up! You must take this at same time from all your indexers to get a consistent backup. I really like to empty test etc. environment for restoration!

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...