Deployment Architecture

How do I thaw frozen buckets in a multi-site indexer cluster?

prakash007
Builder
  1. We have identified few frozen(db_*) buckets to thaw.
  2. We are a multisite indexer cluster(6.5.4), can we rebuild the buckets on one of the indexer in the cluster and restart splunkd on the indexer OR we have to do a rolling restart from Cluster Master?
  3. Can we rebuild the buckets on the test machine, and copy the rebuilt buckets to one of the indexer(thawed_dir) in the cluster?
  4. In case what if we rebuild the buckets on a test machine which is a Splunk 7.0 and copy the buckets to an indexer(v6.5.4)?

I am looking for a least disruptive process to get back the data.

0 Karma

cmeo
Contributor

Can this problem be solved using a standalone search peer which is just for this purpose? In some places I've worked putting the production cluster into maintenance mode to load old data is simply not an option.

There must be a better way. It seems needlessly restrictive and complicated to have to restore the buckets on the cluster nodes it first came from. Enhancement needed?

adonio
Ultra Champion

hello there,

please read here:
https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Restorearchiveddata
as for question 2, never restart a single indexer in the cluster by itself. you can go for maintenance mode, thaw the buckets to the indexer they were rolled out from - make sure GUID matches, restart that indexer and then disable maintenance mode.
read more here:
https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Restorearchiveddata#Clustered_data_thawi...
as for question 3, the challenge on test machine is that the buckets are marked with the indexers guid
would recommend to do the following:
find all data needed to be thawed, best would be if its all from same indexer.
place cluster in maintenance mode, thaw the data, get verify its searchable, disable maintenance mode

hope it helps

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...