Splunk ITSI

kvstore_to_json.py missing -l option for partial ITSI object restore

amartin6
Path Finder

Using ITSI 4.3.0, attempting to do a partial restore via CLI, referencing https://docs.splunk.com/Documentation/ITSI/4.1.0/Configure/kvstore_to_json.pyoperations#Perform_a_pa...

The kvstore_to_json.py file is missing the -l option that is used to specify the path for the rules file, tried with a one and capital L , but neither of those options are in the file either, also looked/grepped for the word "rule" out of the python file but doesn't exist.

[splunk~]$ bin/splunk cmd python etc/apps/SA-ITOA/bin/kvstore_to_json.py -u admin -p ourpassword -f $SPLUNK_HOME/var/itsi/backups/manualbkps/Aug2 -l etc/apps/SA-ITOA/bin/rules.json -i -d -y -n
Usage: kvstore_to_json.py [options]

kvstore_to_json.py: error: no such option: -l
[splunk~]$

The documentation specifies partial restores can only be done via CLI and not GUI, I went back through the document to version 4.1.0 and its not a new feature, just missing? https://docs.splunk.com/Documentation/ITSI/latest/Configure/BackupandRestoreITSIconfig

0 Karma
1 Solution

amartin6
Path Finder

Feature removed in 4.3:
The old partial backup/restore options from the CLI were removed in ITSI 4.3.0 and was deprecated in 4.2.0.
https://docs.splunk.com/Documentation/ITSI/4.3.0/ReleaseNotes/Removedfeatures

View solution in original post

0 Karma

amartin6
Path Finder

Feature removed in 4.3:
The old partial backup/restore options from the CLI were removed in ITSI 4.3.0 and was deprecated in 4.2.0.
https://docs.splunk.com/Documentation/ITSI/4.3.0/ReleaseNotes/Removedfeatures

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...