Deployment Architecture

Known issues with backup systems

gcusello
SplunkTrust
SplunkTrust

Hi at all,
I have a Splunk server all-in-one, version 6.5.2 running on Windows 2012/R2.
There is a backup system based on HP Data Protector 9 that perform a weekly full backup and a daily incremental backup.
Backup was OK until three week ago when incremental backup passed from the usually around 3 GB/day to 65 GB/day and duration passed from 1 hour to 7-8 hours.
There wasn't any reason for this growth, but I noted that usually there is an error "device busy" on some files in _internaldb folder.

So someone knows any known issue using HP Data Protector or another backup system?
Someone registered similar problems?

Thank you.
Bye.
Giuseppe

0 Karma
1 Solution

gfuente
Motivator

Hello

Are you excluding the Hot Buckets from the backup? Those folders can´t be backup with regular backup tools.

You can force the buckets roll to warm:

http://docs.splunk.com/Documentation/Splunk/6.5.3/Indexer/Backupindexeddata#Rolling_buckets_manually...

regards

View solution in original post

gfuente
Motivator

Hello

Are you excluding the Hot Buckets from the backup? Those folders can´t be backup with regular backup tools.

You can force the buckets roll to warm:

http://docs.splunk.com/Documentation/Splunk/6.5.3/Indexer/Backupindexeddata#Rolling_buckets_manually...

regards

Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...