Splunk Search

rolling hot db to warm in 6.2: getting Unknown search command 'oldsearch'

xueshanf
Explorer

I am following this documentation: http://wiki.splunk.com/Community:BestPracticesForBackingUp to try to force a hot-to-warm db rolling. The splunk version is 6.2.2, free version.

./splunk search '| oldsearch !++cmd++::roll' -auth splunk

Unknown search command 'oldsearch'

Any ideas what I am missing?

Thanks!

Xueshan

Tags (2)
0 Karma
1 Solution

ChrisG
Splunk Employee
Splunk Employee

Try using the information in the Back up indexed data topic in the official documentation. It includes the CLI command for manually rolling hot to warm, as well as information about why you might not want to.

View solution in original post

ChrisG
Splunk Employee
Splunk Employee

Try using the information in the Back up indexed data topic in the official documentation. It includes the CLI command for manually rolling hot to warm, as well as information about why you might not want to.

xueshanf
Explorer

The hot to warm rolling commands in that documentation works. I am running Splunk in a docker container and need to run a backup job to put databases in a S3 bucket. There seems a lot pros and cons to consider if and when a hot db should be included in the backup plan. The documentation It's very helpful. Thanks!

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...