Folks,
Can you help me please?
I'm trying to restore buckets for the month of December 2019 on my Splunk instance.
I followed the procedure described in this link:
https://docs.splunk.com/Documentation/Splunk/7.2.0/Indexer/Restorearchiveddata
But I can't do the restoration.
bucket files are 4.2+.
After countless attempts, I changed the bucket name and it still doesn't work.
I stopped the indexer to restore the data and received the message below:
fsck from util-linux 2.23.2
Usage: fsck.ext2 [-panyrcdfvtDFV] [-b superblock] [-B blocksize]
[-I inode_buffer_blocks] [-P process_inode_size]
[-l | -L bad_blocks_file] [-C fd] [-j external_journal]
[-E extended-options] device
Emergency help:
-p Automatic repair (no questions)
-n Make no changes to the filesystem
-y Assume "yes" to all questions
-c Check for bad blocks and add them to the badblock list
-f Force checking even if filesystem is marked clean
-v Be verbose
-b superblock Use alternative superblock
-B blocksize Force blocksize when looking for superblock
-j external_journal Set location of the external journal
-l bad_blocks_file Add to badblocks list
-L bad_blocks_file Set badblocks list
There have been many changes in indexes between Version 4 and 7 (and 😎
I would open a support ticket for this, as they will be more able to give you a solution which is robust and repeatable.