Getting Data In

How to restore logs from frozen bucket?

vnguyen46
Contributor

Hi - in frozen\index\colddb, I have the following files (db_ and rb_)
[splunk@spkpnxl1 wineventlog]$ cd colddb
[splunk@spkpnxl1 colddb]$ ls
db_1564149292_1564145928_6839_1741185A-25EA-4E95-9BBD-447DB7D77D6E
rb_1564419759_1564416947_13512_E3EF5E9B-B5C5-4352-B9DA-61B24C683D2B

How can I restore/re-thaw these files?
Thanks,

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Copy the bucket(s) into the appropriate thaweddb directory, as specified in indexes.conf. Then run the splunk rebuild command on the indexer. You don't need to worry about the rb_* buckets as they're replicates of buckets stored elsewhere.
See https://docs.splunk.com/Documentation/Splunk/7.3.1/Indexer/Restorearchiveddata#Thaw_a_4.2.2B_archive for details.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Copy the bucket(s) into the appropriate thaweddb directory, as specified in indexes.conf. Then run the splunk rebuild command on the indexer. You don't need to worry about the rb_* buckets as they're replicates of buckets stored elsewhere.
See https://docs.splunk.com/Documentation/Splunk/7.3.1/Indexer/Restorearchiveddata#Thaw_a_4.2.2B_archive for details.

---
If this reply helps you, Karma would be appreciated.

kvm
Explorer

@richgalloway how do I run the rebuild command for multiple files?

I'm trying to rebuild the logs for 3 months, and I have hundreds of files, instead of running the rebuild command for each file one by one, is there any other way to run bulk? maybe wildcard or something?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Write a script to rebuild the files.

---
If this reply helps you, Karma would be appreciated.

vnguyen46
Contributor

Thank you so much. In the indexes.conf file, I have:
[wineventlog]
homePath = volume:primary/wineventlog/db
coldPath = volume:cold/wineventlog/colddb
thawedPath = $SPLUNK_DB/wineventlog/thaweddb
frozenTimePeriodInSecs = 5768000 (~67 days)
For some reasons, I don't see any files in the colddb folder older than 45 days. Do you know what caused the issue and what I need to do if I need to keep the log for 180 days?

Thank you,

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This should be a separate question.
Once Splunk freezes a bucket it no longer will do anything with it. It's up to you to manage the frozen buckets so they remain available for the desired time.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnguyen46
Contributor

Thank you.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...