Getting Data In

Can't access data after DB migration

antinym
New Member

I backed up all my data, moved it to a larger secondary drive. Uninstalled and re-installed splunk on top of the backed up data on the secondary drive. Now when I search I can not see any data before the backup/install. It's a windows box, and splunk 4.1.3. What can I do?

0 Karma

Mick
Splunk Employee
Splunk Employee

Where does your backed up data live and do you have the SPLUNK_DB variable set correctly in %SPLUNK_HOME\etc\splunk-launch.conf?

Or do you have your $SPLUNK_HOME\etc\system\local\indexes.conf pointing to the backup location?

Basically what I'm asking is, have you told your new Splunk instance where to find the existing data? An easy solution would be to just copy all of your index buckets into the %SPLUNK_HOME\var\lib\splunk\defaultdb\db directory, assuming it's a brand new instance and you haven't yet made any changes to the files mentioned above.

antinym
New Member

I can see lots of files and directories in %SPLUNK_HOME\var\lib\splunk\defaultdb\db

it looks like the following but with different dates and numbers, obviously.

04/07/2010 09:57 AM

db_1219018015_1219018015_24
04/07/2010 09:57 AM 0 db_1219018015_1219018015_24.sentinel
06/05/2010 02:10 PM db_1223363806_1192723204_31
06/05/2010 02:10 PM 0 db_1223363806_1192723204_31.sentinel
04/05/2010 09:41 AM db_1226784675_1219014387_2

0 Karma

antinym
New Member

The %SPLUNK_HOME\etc\splunk-launch.conf is not set. According to the info in the file, it should use the parent directory (D:\splunk) which is where all the files were copied.

I don't have a $SPLUNK_HOME\etc\system\local\indexes.conf
but that directory does exist with other conf files

I did copy the %SPLUNK_HOME\var\lib\splunk\defaultdb\db first, then uninstalled splunk, and re-installed. My inputs.conf is working, but still no access to the old info.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...