Splunk Search

How to use command "splunk resurrect".

melonman
Motivator

Hi,

question about restoration of indexed data. I know how to restore(or search old) indexes data by putting necessary files in a thaweddb.

I would like to know how to use command "splunk resurrect", to restore the index specified period of time by the "splunk resurrect" command.

http://www.splunk.com/base/Documentation/4.1.2/Admin/CLIadmincommands

I am referring to the page above, but I can't get successful result. I would appreciate if you could explain how to use "splunk resurrect" with some example case.

Thank you!

Tags (1)
1 Solution

rroberts
Splunk Employee
Splunk Employee

From the CLI type... splunk help resurrect. Are you running the command like so....

splunk resurrect /tmp/myarchive/location myindex 01/01/2000:00:00:00 01/01/2001:00:00:00

/tmp/myarchive/location = path to archive file myindex = name of index to resurrect to.

View solution in original post

rroberts
Splunk Employee
Splunk Employee

From the CLI type... splunk help resurrect. Are you running the command like so....

splunk resurrect /tmp/myarchive/location myindex 01/01/2000:00:00:00 01/01/2001:00:00:00

/tmp/myarchive/location = path to archive file myindex = name of index to resurrect to.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...