Hello All, I have 3 indexer in cluster and data is being stored in the NAS server. and for one server data is stored in cold logs on a mounted storage. I have copied the data from NAS to 2 s...
Hi,
I've archivedindexeddata into location "D:\Program Files\Splunk\myfrozenarchive" and now myfrozenarchive folder has to folders
db_1364755264_1356979773_16
d...
Hi All,
I want to get Archiveddata from Frozen buckets for a certain time frame. The index which i am trying to fetch is related to windows event logs. Is their any script available to a...
...ehind this method is that if for any reason I ever needed to restore the archiveddata for searching I could simply setup a new Splunk indexer, attach the archived EBS volume, and point a search h...
....2 and higher, you can thaw data on any indexer instance, not just the one that it originated on.
"For the most part, you can restore an
archive to any instance of the
indexer, not just the o...
...t make sense to have backups from warm, cold, and archived/frozen indexeddata on the Splunk servers taken daily and then sent over to an OCI bucket? Splunk deployments on OCI aren't common, so I'm i...
After I restore the archiveddata in thawed path and rebuild the index - Splunk recognizes the data.
What is the life-time of the data residing in the thawed path? Is there any default retention p...
Hi ,
My file got indexed. Unfortunately both the actual file and the indexeddata got deleted but we have backup for indexeddata.
We are trying to retrieve the raw data from indexeddata b...
...ime based seems to be another. My gut says this would be based on indexed time but not sure how historical data and timestamps play into bucket creation.