Splunk Search
Highlighted

After moving DB folders back into Thaweddb, then rebuilt and restarted the indexer, why are events still not searchable?

Explorer

While I wait for Splunk support to get back to me on my case, I'll pose the problem here.

After moving DB folders back into Thaweddb, I completed the needed steps from the 6.3.4 documentation to rebuild and restart the indexer.

http://docs.splunk.com/Documentation/Splunk/6.3.4/Indexer/Restorearchiveddata

Unfortunately, the events are still not searchable. What else can I try to get the events searchable?

0 Karma
Highlighted

Re: After moving DB folders back into Thaweddb, then rebuilt and restarted the indexer, why are events still not searchable?

Explorer

After trolling through more backup files, I found a hot bucket related to the warm bucket that I previous had. Not at much data, but it will help.

I found this GEM - https://answers.splunk.com/answers/13032/is-there-a-way-to-restore-hot-buckets.html

The only thing I can think of is the warm bucket is corrupt.

0 Karma