Splunk Search

Restoring old data to Splunk Indexer Cluster

shiv1593
Communicator

Hi All,

We have 7 indexers and they are in a cluster. Our hot and warm buckets are stored inside the local storage of the Indexers ($Splunk_Home/var/lib/splunk) and our colddb is in a NAS storage drive, mounted on our Indexers (volume:drive/index/colddb).

Recently, due to a strange issue, the data inside the colddb went missing for 2 Indexes. We can't find it on the NAS drive as well. Fortunately, our NAS drives are backed up by our backup team. So we have a copy of that data and want it back on our mounted NAS drive and Splunk to search it again, with the same old dates and times, like it was always there.

Can anyone suggest how can we do it? Do we have to reindex all the data (It's huge and the data is from January 2019 to October 2019) or will restoring the data back to the NAS drive will suffice?

Any suggestions and solutions are highly welcomed and appreciated.

Thanks in advance,
Shiv

0 Karma
1 Solution

woodcock
Esteemed Legend

Just copy it back and restart the Cluster Master and rolling restart the Indexers.

View solution in original post

woodcock
Esteemed Legend

Just copy it back and restart the Cluster Master and rolling restart the Indexers.

shiv1593
Communicator

Hello Gregg. Thank you for the suggestion. We have begun the process of restoring the data. Will update again once it's done, along with the rolling restart.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...