Installation

Rebuild 4.1 Bucket in 4.2

ephemeric
Contributor

Greetz,

So I have tried:

./splunk _internal call /data/indexes/main/rebuild-metadata-and-manifests

in a 4.2.3 instance but a whole lot of XML goes flying by and nothing seems to happen.

Looking at index health I see many thawed buckets but with an event count of 0!

I did manage to rebuild the 4.2 buckets. This instance was upgraded from 4.7.1 hence the bucket mix.

Please help!!!

Tags (2)
0 Karma
1 Solution

ephemeric
Contributor

Me being stupid as usual.

This was not so clear to me.
You have to uncompress ALL of the *.gz files in the bucket and rawdata/.
I thought that if the bucket itself was compressed what this instruction was alluding to.

http://docs.splunk.com/Documentation/Splunk/latest/admin/Restorearchiveddata#Thaw_a_pre-4.2_archive

2. If the bucket was compressed when originally archived, uncompress the contents in the thawed directory.

View solution in original post

0 Karma

ephemeric
Contributor

Me being stupid as usual.

This was not so clear to me.
You have to uncompress ALL of the *.gz files in the bucket and rawdata/.
I thought that if the bucket itself was compressed what this instruction was alluding to.

http://docs.splunk.com/Documentation/Splunk/latest/admin/Restorearchiveddata#Thaw_a_pre-4.2_archive

2. If the bucket was compressed when originally archived, uncompress the contents in the thawed directory.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...