Getting Data In

Restoring specific source from frozen

splunkreal
Motivator

Hello guys,

we need to restore frozen data, however is it possible to choose which source to restore (not all sources), if yes, how?

Thanks.

* If this helps, please upvote or accept solution if it solved *
0 Karma

xpac
SplunkTrust
SplunkTrust

Hey,
when thawing (restoring) frozen data, you're limited to the name of the index, and the time range of the bucket(s) of that index you want to restore.
You can find details on how to do this in the "Restore archived indexed data" doc.

Hope that helps - if it does I'd be happy if you would upvote/accept this answer, so others could profit from it. 🙂

Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...