Hello Experts,
We have migrated to new hardware after old data is backed up , new environment has last 2 months of data . Now we want to restore old data onto a standalone server to perform some searches .
Highlights
--> old backup has primary and replication buckets as it was cluster backup.
--> we are planning to setup a test machine(indexer/search head) for the above and ask storage team to mount (~450TB (primary and secondary ) buckets).
Do you think it is a right approach ? is there anything that we need to consider before we ask a test machine (8GB RAM , 4 CPU) and storage team to mount 450TB(backup) to this test machine .
it is just old data , Both setups were running in parallel for like a month or so, once all the log sources shifted successfully to new setup we stopped using old setup . I am sure mostly the data will be in warm and cold bucket as when we stop/restart old splunk buckets should have moved to warm .
Hi @vikas_gopal,
at first the configuration you defined isn't recommended by Splunk, but its isn't a production system, so it could go.
About the idea to have a stand alone server containing the old data (that are in an Indexer Cluster), you could use one of the Cluster search peers disconnecting it from the old cluster, you have to put attention to the steps to follow:
It isn't an usual procedure and I'm not sure that it was tested, but it should work.
Ciao.
Giuseppe
Thank you ,
This is a very good suggestion but unfortunately all old server are decommissioned. We only have data backup in buckets form . I am pretty sure they are warm and cold . Hence it is decided to have a standalone and mount the data backup storage and start searching it .
Hi @vikas_gopal,
the main problem is that probably you have the backup in clustered format: I'm not sure that it's possible to restore it without a cluster!
Let me know if I can help you more.
Ciao.
Giuseppe
P.S.: Karma Points are appeciated 😉
yeah thank you in advance