Hi guys, I have a particular situation and I didn't found anything useful googling.
On our on prem QRadar instance, we got a critical problem that forced us to perform a snapshot restore in a urgent manner.
Due this, we counldn't perform a save of indexed data and so, after the restore, we have no logs in time period between snapshot image (20/07) and restoration date (03/08). Now this data could be required.
About reindexing data, I found this: QRadar: Creating event and flow indexes after restoring data on a managed host appliance but, correct if I'm wrong, this works if data has been indexed and then deleted. In our scenario, due the snapshot restore, it's like data has never been indexed by QRadar, so this procedure is not fine.
My question so is: is there a way to reinsert this data (that are still on data sources) from log sources to QRadar?
------------------------------
Luca Sepe
------------------------------