Splunk Search

rolling hot db to warm in 6.2: getting Unknown search command 'oldsearch'

xueshanf
Explorer

I am following this documentation: http://wiki.splunk.com/Community:BestPracticesForBackingUp to try to force a hot-to-warm db rolling. The splunk version is 6.2.2, free version.

./splunk search '| oldsearch !++cmd++::roll' -auth splunk

Unknown search command 'oldsearch'

Any ideas what I am missing?

Thanks!

Xueshan

Tags (2)
0 Karma
1 Solution

ChrisG
Splunk Employee
Splunk Employee

Try using the information in the Back up indexed data topic in the official documentation. It includes the CLI command for manually rolling hot to warm, as well as information about why you might not want to.

View solution in original post

ChrisG
Splunk Employee
Splunk Employee

Try using the information in the Back up indexed data topic in the official documentation. It includes the CLI command for manually rolling hot to warm, as well as information about why you might not want to.

xueshanf
Explorer

The hot to warm rolling commands in that documentation works. I am running Splunk in a docker container and need to run a backup job to put databases in a S3 bucket. There seems a lot pros and cons to consider if and when a hot db should be included in the backup plan. The documentation It's very helpful. Thanks!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...