Getting Data In

How to restore logs from frozen bucket?

vnguyen46
Contributor

Hi - in frozen\index\colddb, I have the following files (db_ and rb_)
[splunk@spkpnxl1 wineventlog]$ cd colddb
[splunk@spkpnxl1 colddb]$ ls
db_1564149292_1564145928_6839_1741185A-25EA-4E95-9BBD-447DB7D77D6E
rb_1564419759_1564416947_13512_E3EF5E9B-B5C5-4352-B9DA-61B24C683D2B

How can I restore/re-thaw these files?
Thanks,

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Copy the bucket(s) into the appropriate thaweddb directory, as specified in indexes.conf. Then run the splunk rebuild command on the indexer. You don't need to worry about the rb_* buckets as they're replicates of buckets stored elsewhere.
See https://docs.splunk.com/Documentation/Splunk/7.3.1/Indexer/Restorearchiveddata#Thaw_a_4.2.2B_archive for details.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Copy the bucket(s) into the appropriate thaweddb directory, as specified in indexes.conf. Then run the splunk rebuild command on the indexer. You don't need to worry about the rb_* buckets as they're replicates of buckets stored elsewhere.
See https://docs.splunk.com/Documentation/Splunk/7.3.1/Indexer/Restorearchiveddata#Thaw_a_4.2.2B_archive for details.

---
If this reply helps you, Karma would be appreciated.

kvm
Explorer

@richgalloway how do I run the rebuild command for multiple files?

I'm trying to rebuild the logs for 3 months, and I have hundreds of files, instead of running the rebuild command for each file one by one, is there any other way to run bulk? maybe wildcard or something?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Write a script to rebuild the files.

---
If this reply helps you, Karma would be appreciated.

vnguyen46
Contributor

Thank you so much. In the indexes.conf file, I have:
[wineventlog]
homePath = volume:primary/wineventlog/db
coldPath = volume:cold/wineventlog/colddb
thawedPath = $SPLUNK_DB/wineventlog/thaweddb
frozenTimePeriodInSecs = 5768000 (~67 days)
For some reasons, I don't see any files in the colddb folder older than 45 days. Do you know what caused the issue and what I need to do if I need to keep the log for 180 days?

Thank you,

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This should be a separate question.
Once Splunk freezes a bucket it no longer will do anything with it. It's up to you to manage the frozen buckets so they remain available for the desired time.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnguyen46
Contributor

Thank you.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...