Hi,
I'm testing thawing of some frozen data and it's not working. I have thawed some previously frozen data and am expecting to see it in the search, but the search result returned is empty.
Some questions:
- Could this a bug (I'm following the recommended method from Splunk admin training)?
- How could I take my investigation further?
Procedure:
stop Splunk
copy frozen data (bucket) to a thawed directory
run rebuild command - Splunk rebuilds (this appears to work as I see the metadata files are created (Sources.data, bloomfilter, Hosts.data etc).
start Splunk
search (index=itops earliest = -365d). Result: 0 events - No results found. Try expanding the time range.
A few more details:
- Running SE version 7.3
- the data is from 2 weeks ago (I set the data in the index to age out/freeze after two days)
- this is a test platform
- Seeing some weird logs in the internal index that I don't understand:
7/9/19 5:14:53.226 PM 07-09-2019 17:14:53.226 +0200 INFO DatabaseDirectoryManager - Getting size on disk: Unable to get size on disk for bucket id=itops~5~8D8C5421-3FB9-4E28-A7DA-D62472398A71 path="C:\Program Files\Splunk\var\lib\splunk\itops\thaweddb\db_1561999955_1558706749_5" (This is usually harmless as we may be racing with a rename in BucketMover or the S2SFileReceiver thread, which should be obvious in log file; the previous WARN message about this path can safely be ignored.) caller=getBucketManifestValues
host = XXXXXX
source = C:\Program Files\Splunk\var\log\splunk\splunkd.log
sourcetype = splunkd
... View more