Splunk Search

rolling hot db to warm in 6.2: getting Unknown search command 'oldsearch'

xueshanf
Explorer

I am following this documentation: http://wiki.splunk.com/Community:BestPracticesForBackingUp to try to force a hot-to-warm db rolling. The splunk version is 6.2.2, free version.

./splunk search '| oldsearch !++cmd++::roll' -auth splunk

Unknown search command 'oldsearch'

Any ideas what I am missing?

Thanks!

Xueshan

Tags (2)
0 Karma
1 Solution

ChrisG
Splunk Employee
Splunk Employee

Try using the information in the Back up indexed data topic in the official documentation. It includes the CLI command for manually rolling hot to warm, as well as information about why you might not want to.

View solution in original post

ChrisG
Splunk Employee
Splunk Employee

Try using the information in the Back up indexed data topic in the official documentation. It includes the CLI command for manually rolling hot to warm, as well as information about why you might not want to.

xueshanf
Explorer

The hot to warm rolling commands in that documentation works. I am running Splunk in a docker container and need to run a backup job to put databases in a S3 bucket. There seems a lot pros and cons to consider if and when a hot db should be included in the backup plan. The documentation It's very helpful. Thanks!

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...