Splunk Search

Restoring old data to Splunk Indexer Cluster

shiv1593
Communicator

Hi All,

We have 7 indexers and they are in a cluster. Our hot and warm buckets are stored inside the local storage of the Indexers ($Splunk_Home/var/lib/splunk) and our colddb is in a NAS storage drive, mounted on our Indexers (volume:drive/index/colddb).

Recently, due to a strange issue, the data inside the colddb went missing for 2 Indexes. We can't find it on the NAS drive as well. Fortunately, our NAS drives are backed up by our backup team. So we have a copy of that data and want it back on our mounted NAS drive and Splunk to search it again, with the same old dates and times, like it was always there.

Can anyone suggest how can we do it? Do we have to reindex all the data (It's huge and the data is from January 2019 to October 2019) or will restoring the data back to the NAS drive will suffice?

Any suggestions and solutions are highly welcomed and appreciated.

Thanks in advance,
Shiv

0 Karma
1 Solution

woodcock
Esteemed Legend

Just copy it back and restart the Cluster Master and rolling restart the Indexers.

View solution in original post

woodcock
Esteemed Legend

Just copy it back and restart the Cluster Master and rolling restart the Indexers.

shiv1593
Communicator

Hello Gregg. Thank you for the suggestion. We have begun the process of restoring the data. Will update again once it's done, along with the rolling restart.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...