Why can’t I see all my data for my Snare Server?


SUMMARY

Jul 13, 2015

After an upgrade it is possible that you may only see some data and not all of it. This may be due to metadata not rebuilding or the server was rebooted while it was rebuilding, and therefore did not restart.

To rerun the metadata generation to rebuild the indices, login to the Snare Server console and from the command line change directory to the archive:
cd /data/SnareArchive

To regenerate the data for year 2015, then run the wildcard match as required for the individual day/month as required:
/data/Snare/MetaData/Supporting/regenerate 2015*