I am running Splunk Enterprise 8.0.6 and have Hadoop Data Roll configured, using Hadoop 3.2.1 with Java 1.8.0_282-b08. I have a virtual index configured toarchive an indexto AWS S3. The Hadoop D...
We are getting a bunch of the following errors as our AWS EC2 indexers try toarchive buckets toS3 with Hadoop Data Roll.
How can we fix them or will they get retried and we can ignore them, if s...
Here's the situation - we have a non-developer, new toSplunk, without access toHadoop (or any basic understanding of it) trying to backup indexed data to AWS S3. The documentation provides a lot o...
I follow the instructions in [the documentation for archiving toS3 in 6.5.0 http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/ArchivingSplunkindexestoS3
but Splunk still can't find the j...
I am seeing the following error message while trying toarchivetoS3. The logs are from "splunk_archiver.log". Any pointer as how to fix this ?
2019-09-09 06:09:11.127 -0700 ERROR Roller - E...
Hi,
I'm searching for the documentation for the new 6.5 hadoop data roll feature, and unable to find it. Can someone point me to it? Or where it's setup within Splunk? Nothing obvious stands o...
Recently I have archived buckets of _internal index(older than 90 days) from one site of splunkindexers toHadoop cluster using https://docs.splunk.com/Documentation/Splunk/8.0.3/Indexer/Archiv...
...ummarize --human-readable --recursive s3://splunkdockbucket/
Total Objects: 425
Total Size: 7.7 GiB
```
How to configure indexes.conf toonly archive frozen data...?
...oldToFrozenscript.py
This will archive data to a particular directory that we mention in indexes.conf.
However it faces problems in cases of clustered architecture due to same multiple buckets being c...