Splunk Search

After moving DB folders back into Thaweddb, then rebuilt and restarted the indexer, why are events still not searchable?

thoban
Explorer

While I wait for Splunk support to get back to me on my case, I'll pose the problem here.

After moving DB folders back into Thaweddb, I completed the needed steps from the 6.3.4 documentation to rebuild and restart the indexer.

http://docs.splunk.com/Documentation/Splunk/6.3.4/Indexer/Restorearchiveddata

Unfortunately, the events are still not searchable. What else can I try to get the events searchable?

0 Karma

thoban
Explorer

After trolling through more backup files, I found a hot bucket related to the warm bucket that I previous had. Not at much data, but it will help.

I found this GEM - https://answers.splunk.com/answers/13032/is-there-a-way-to-restore-hot-buckets.html

The only thing I can think of is the warm bucket is corrupt.

0 Karma
Get Updates on the Splunk Community!

Index This | Why do they call it hyper text?

November 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

State of Splunk Careers 2023: Career Resilience and the Continued Value of Splunk

For the past three years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

The Great Resilience Quest: 9th Leaderboard Update

The ninth leaderboard update (11.9-11.22) for The Great Resilience Quest is out >> Kudos to all the ...