From the CLI:
./splunk _internal call /data/indexes/<index_name>/roll-hot-buckets –auth <admin_username>
(you will be prompted for the password)
From the CLI:
./splunk _internal call /data/indexes/<index_name>/roll-hot-buckets –auth <admin_username>
(you will be prompted for the password)
what is the command or procedure to roll buckets on windows?
If you do this when you have splund off it does not work. If you do this when it is running, though it creates a new cold bucket you still have a hot one. If you are trying to move the index, how do you do that when the documentation says not to copy hot buckets?
This is for 4.x.
For 3.4.5 it is:
/opt/splunk/bin/splunk search '| oldsearch !++cmd++::roll' -auth