Deployment Architecture

Backing up hot buckets on NetApp

Branden
Builder

According to the documentation:
"To back up hot buckets as well, you need to take a snapshot of the files, using a tool like VSS (on Windows/NTFS), ZFS snapshots (on ZFS), or a snapshot facility provided by the storage subsystem. If you do not have a snapshot tool available, you can manually roll a hot bucket to warm and then back it up, as described below. However, this is not generally recommended, for reasons also discussed below. "

We will be moving our Splunk storage to our NetApp, which employs a product we purchased called SnapDrive. I don't know too much about it, but, among other things, it allows us to take snap shots of our data for quick back-ups/restores. (Our storage team manages this stuff, fortunately.)

Does anyone have any experience with this product/procedure? Would this be a suitable substitute for rolling hot buckets->warm buckets then doing incrementals?

Thanks!

Tags (2)
1 Solution

dwaddle
SplunkTrust
SplunkTrust

I assume since you are using SnapDrive, this is a NetApp connected via FCP or iSCSI and not NFS. Splunk does not recommend use of NFS for hot buckets.

SnapDrive snapshots should be sufficient for backing up hot buckets.

Also, Splunk 4.2 includes changes that make hot bucket recovery more reliable. So, while using SnapDrive snapshots for your backups should be good enough, also having your indexers on Splunk 4.2 should add some additional confidence.

View solution in original post

dwaddle
SplunkTrust
SplunkTrust

I assume since you are using SnapDrive, this is a NetApp connected via FCP or iSCSI and not NFS. Splunk does not recommend use of NFS for hot buckets.

SnapDrive snapshots should be sufficient for backing up hot buckets.

Also, Splunk 4.2 includes changes that make hot bucket recovery more reliable. So, while using SnapDrive snapshots for your backups should be good enough, also having your indexers on Splunk 4.2 should add some additional confidence.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...