Hi,
I am looking for a documentation which describes the necessary steps in case of a disaster recovery (the host where Splunk Enterprise is installed crashes at some point) when I have only one Splunk Enterprise and receiving from some forwarders.
Let's suppose all indexed data backups have been done regularly (under `$SPLUNK_HOME/var/lib/splunk/`/db).
What is the ocfficial procedure of restoring Splunk? I found helpful this page: http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Backupindexeddata
Thanks a lot,
Skender
↧