Hi - in frozen\index\colddb, I have the following files (db_ and rb_)
[splunk@spkpnxl1 wineventlog]$ cd colddb
[splunk@spkpnxl1 colddb]$ ls
db_1564149292_1564145928_6839_1741185A-25EA-4E95-9BBD-447DB7D77D6E
rb_1564419759_1564416947_13512_E3EF5E9B-B5C5-4352-B9DA-61B24C683D2B
How can I restore/re-thaw these files?
Thanks,
Copy the bucket(s) into the appropriate thaweddb directory, as specified in indexes.conf. Then run the splunk rebuild
command on the indexer. You don't need to worry about the rb_* buckets as they're replicates of buckets stored elsewhere.
See https://docs.splunk.com/Documentation/Splunk/7.3.1/Indexer/Restorearchiveddata#Thaw_a_4.2.2B_archive for details.
Copy the bucket(s) into the appropriate thaweddb directory, as specified in indexes.conf. Then run the splunk rebuild
command on the indexer. You don't need to worry about the rb_* buckets as they're replicates of buckets stored elsewhere.
See https://docs.splunk.com/Documentation/Splunk/7.3.1/Indexer/Restorearchiveddata#Thaw_a_4.2.2B_archive for details.
@richgalloway how do I run the rebuild command for multiple files?
I'm trying to rebuild the logs for 3 months, and I have hundreds of files, instead of running the rebuild command for each file one by one, is there any other way to run bulk? maybe wildcard or something?
Write a script to rebuild the files.
Thank you so much. In the indexes.conf file, I have:
[wineventlog]
homePath = volume:primary/wineventlog/db
coldPath = volume:cold/wineventlog/colddb
thawedPath = $SPLUNK_DB/wineventlog/thaweddb
frozenTimePeriodInSecs = 5768000 (~67 days)
For some reasons, I don't see any files in the colddb folder older than 45 days. Do you know what caused the issue and what I need to do if I need to keep the log for 180 days?
Thank you,
This should be a separate question.
Once Splunk freezes a bucket it no longer will do anything with it. It's up to you to manage the frozen buckets so they remain available for the desired time.
Thank you.