Assuming you are doing this in version 4.1, let's say you have the following archived bucket:
db_1274129994_1273525194_0
Example:
# cp -r db_1274129994_1273525194_0 $SPLUNK_HOME/var/lib/splunk/defaultdb/thaweddb/temporary-db_1274129994_1273525194_0
Note that, while unlikely, make sure that there isn't a bucket naming conflict. In other words, there should be no existing bucket with the same name in that directory. If so, rename the bucket by changing the bucket id (in the example above, the bucket id is 0.)
Example:
# $SPLUNK_HOME/bin/splunk _internal call /data/indexes/main/rebuild-metadata-and-manifests -auth admin:changeme
You can restore archived data by moving the archive into the thawed directory, $SPLUNK_HOME/var/lib/splunk/defaultdb/thaweddb.
further details here:
http://www.splunk.com/base/Documentation/latest/Admin/Restorearchiveddata
Assuming you are doing this in version 4.1, let's say you have the following archived bucket:
db_1274129994_1273525194_0
Example:
# cp -r db_1274129994_1273525194_0 $SPLUNK_HOME/var/lib/splunk/defaultdb/thaweddb/temporary-db_1274129994_1273525194_0
Note that, while unlikely, make sure that there isn't a bucket naming conflict. In other words, there should be no existing bucket with the same name in that directory. If so, rename the bucket by changing the bucket id (in the example above, the bucket id is 0.)
Example:
# $SPLUNK_HOME/bin/splunk _internal call /data/indexes/main/rebuild-metadata-and-manifests -auth admin:changeme
There's still a thaweddb in 4.3 so I will assume that this works the same way.
how whould that work on 4.3.x... still this way or did it change and you have to put the bucket somewhere else?