Skip to main content
Question

Replay Splunk Data by reading the Splunk frozen buckets

  • March 11, 2025
  • 1 reply
  • 22 views

Have anybody tried to replay Splunk frozen buckets from AWS S3

1 reply

  • Employee
  • March 11, 2025

@David Cavuto may have something in the works for the future. At present, you can use the approach outlined here: https://cribl.io/blog/exporting-splunk-data/ . Disclaimer: I wrote it and it's technically open-sourced (not officially supported by Cribl). You will need to thaw your buckets before using the tool.