Restoring Splunk Data

You can browse and restore backed up Splunk clustered indexes.

Before You Begin

Perform a backup operation.


  1. From the navigation pane, click Protect > Big data.

    The Instances page appears.

  2. Click an instance name.

    The selected instance page appears.

  3. In the Restore column of the subclient, click Restore.

    The Backup content page appears.

  4. Select the check boxes for the individual Splunk indexes that you want to restore, and then click Restore.

    The Restore dialog box appears.

  5. Complete one of the following tasks depending on the type of restore operation you are running:
    • For an in-place restore operation, the destination instance remains the same as the source instance.
    • To perform an out-of-place restore operation, select the Restore to another Splunk instance check box, and then select the destination instance for the restore operation.
  6. To overwrite any existing data with the restored data, select the Unconditionally overwrite if it already exists check box.

    Note: By default, any existing data at the destination is prevented from being overwritten during a restore operation.

  7. Click OK.


A restore job is created. You can monitor the job progress, kill the job, or suspend the job.

For information about monitoring all the jobs in the Command Center environment, see Jobs.

Last modified: 5/26/2020 11:29:28 AM