Start a Conversation

Unsolved

This post is more than 5 years old

D2

1839

October 16th, 2013 11:00

How best to backup Splunk on Windows?

We have Splunk (for the uninitiated, its a SIEM), and I need to backup the log indexes. Right now they are about 1.5TB but are projected to grow to 10TB in the next year. They run on physical Windows servers (Cisco UCS blades) tied to an EMC VNX 5700. Anybody have experience with backing up large volumes of Splunk data? How did you best tackle it? We've tested with Networker and Data Domain and just a straight flat file backup via VSS, but its SLOW.

2 Intern

 • 

14.3K Posts

October 16th, 2013 11:00

Use snapshot on VNX and mount snapshot on proxy and take it from there (under assumption that you could split volumes in such way that splunk logs would be on its own volume which probably is not the case).

October 16th, 2013 11:00

Ok, so I'm not that familiar with the snapshots on VNX, but I get the concepts. I do know also that the VNX supposedly does not support scheduled snaps for block. Do you know if that's correct?

2 Intern

 • 

14.3K Posts

October 16th, 2013 12:00

You can integrate snapshots with NW and use scheduling by backup software.

2 Intern

 • 

14.3K Posts

October 17th, 2013 06:00

I'm talking about PowerSnap itself (without VSS thingy and NMM) or in 8.1 this is now integrated (it is not like PowerSnap, but very much alike).  With PowerSnap, you need license and with new functionality not sure - I guess it depends what kind of licensing model you have (if using capacity license, it will work too).

October 17th, 2013 06:00

Ok, so please bear with me. I'm pouring through documentation, but am still a little fuzzy. What I see is that Networker supposedly can schedule and utilize VNX snapshots because it is aware of the array, but when I use the new client wizard, at the second step, it fails to connect to the client. I specify "Traditional Networker Client" and go next. It then gives the Filesystem as the only application. I click next and get "Unable to connect to host: Please check Networker Security setting and daemon logs...". I checked the logs and found nothing that I could see. Also, I verified that the auth mechanism was the same for server and client.

But regardless I guess, when you talk about snaps, are you talking like using Powersnap or just leveraging VSS snaps? I've used the Powersnap before but only with the NMM 2.4 and SQL & Exchange.

October 29th, 2013 11:00

I do not have capacity license. I have upgraded server and clients to 8.1 now. I noticed it installed the Powersnap service automatically. So now, when I try the "New Client Wizard" it cannot detect my VNX like it should. It says "Unable to find naviseccli command". Naviseccli is installed on the NW server. Not sure what else to do or how to configure it in NW.

2 Intern

 • 

14.3K Posts

October 29th, 2013 12:00

That tool comes from NaviSphere/NaviCLI which was used for config of CLARiiON and VNX later on.  It should be available on control host and application hosts (and proxy nodes that ideally are your media servers).

October 29th, 2013 13:00

Oh duh. I installed it on the client server and it sees it now.

EDIT: Now I'm stuck in the wizard getting "No appropriate filesystems available".

The Splunk servers are boot from SAN Cisco blades with a second data LUN for the Splunk DB's.

2 Intern

 • 

14.3K Posts

October 30th, 2013 05:00

Well, ideally you wish to protect DB file system (in combination with module which will just make sure all is in sync and backup mode).  As to why no appropriate fs found message, I don't know - it may have some check and doesn't find it suitable.  Try to configure it manually and see what you get as an error - it will probably provide better starting point.

No Events found!

Top