Splunk Search

After moving DB folders back into Thaweddb, then rebuilt and restarted the indexer, why are events still not searchable?

thoban
Explorer

While I wait for Splunk support to get back to me on my case, I'll pose the problem here.

After moving DB folders back into Thaweddb, I completed the needed steps from the 6.3.4 documentation to rebuild and restart the indexer.

http://docs.splunk.com/Documentation/Splunk/6.3.4/Indexer/Restorearchiveddata

Unfortunately, the events are still not searchable. What else can I try to get the events searchable?

0 Karma

thoban
Explorer

After trolling through more backup files, I found a hot bucket related to the warm bucket that I previous had. Not at much data, but it will help.

I found this GEM - https://answers.splunk.com/answers/13032/is-there-a-way-to-restore-hot-buckets.html

The only thing I can think of is the warm bucket is corrupt.

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2023 Splunk Career Impact Report

We’ve been shouting it from the rooftops! The findings from the 2023 Splunk Career Impact Report showing that ...

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...