Getting Data In

Rolling cold data to tape

preotesoiu
Path Finder

Hello,
We are planning for a solution to archive cold data to tape and I was wondering which one of these solutions will be better (coldToFrozenDir or coldToFrozenScript).
Initial plan was to use coldToFrozenDir into a separate volume and then have Tivoli Storage Manager to move it to tape but reading through Splunk documentation it appears that coldToFrozenScript is preferred when rolling to tape.
Have you implemented such a solution and what would be the conditions that have to be met in order to have a successful implementation?

1 Solution

inventsekar
Ultra Champion

coldToFrozenScript is the best option as per my view.
- (instead of using coldToFrozenDir and then Tivoli Storage Manager to write to tape, you could directly do this with coldToFrozenScript)
- the cost of Tivoli Storage Manager
- extra configuration and maintenance works, etc..

between, how much data, approx you have or daily license limit please.

View solution in original post

0 Karma

inventsekar
Ultra Champion

coldToFrozenScript is the best option as per my view.
- (instead of using coldToFrozenDir and then Tivoli Storage Manager to write to tape, you could directly do this with coldToFrozenScript)
- the cost of Tivoli Storage Manager
- extra configuration and maintenance works, etc..

between, how much data, approx you have or daily license limit please.

0 Karma

preotesoiu
Path Finder

Thanks.
We are doing several TB daily ingestion.
By the way, do you know if the script will take care of replicated buckets or if that is something we need to consider?

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

It will not. Data rolls individually per indexer, so if you are running index replication, you may want to remove all replicated buckets and only move primaries in your script.

0 Karma

preotesoiu
Path Finder

much appreciated! I have what I need for now to start testing...
G

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...