<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Roll Hot Bucket into warm-Error in Security</title>
    <link>https://community.splunk.com/t5/Security/Roll-Hot-Bucket-into-warm-Error/m-p/174846#M5191</link>
    <description>&lt;P&gt;Which version of Splunk you are using?&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jan 2015 12:59:43 GMT</pubDate>
    <dc:creator>abacus_machine_</dc:creator>
    <dc:date>2015-01-07T12:59:43Z</dc:date>
    <item>
      <title>Roll Hot Bucket into warm-Error</title>
      <link>https://community.splunk.com/t5/Security/Roll-Hot-Bucket-into-warm-Error/m-p/174842#M5187</link>
      <description>&lt;P&gt;I am trying to roll hot bucket using following cmd, and it it throwing error ,with http status=503,&lt;BR /&gt;
Please tell me, where I am doing mistake:&lt;BR /&gt;
C:\Program Files\Splunk\bin&amp;gt;splunk _internal call /data/indexes/olym/roll-hot-buckets -auth admin:changeme&lt;BR /&gt;
QUERYING: '&lt;A href="https://127.0.0.1:8089/services/data/indexes/olym/roll-hot-buckets"&gt;https://127.0.0.1:8089/services/data/indexes/olym/roll-hot-buckets&lt;/A&gt;'&lt;BR /&gt;
FAILED: 'HTTP/1.1 503 Service Unavailable'&lt;BR /&gt;
Content:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;msg type="ERROR"&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In handler 'indexes': could not queue custom action='roll-hot-buckets' for idx=olym&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 10:36:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Roll-Hot-Bucket-into-warm-Error/m-p/174842#M5187</guid>
      <dc:creator>rajuljain1990</dc:creator>
      <dc:date>2015-01-07T10:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: Roll Hot Bucket into warm-Error</title>
      <link>https://community.splunk.com/t5/Security/Roll-Hot-Bucket-into-warm-Error/m-p/174843#M5188</link>
      <description>&lt;P&gt;Is your Splunk running and working? run &lt;CODE&gt;splunk status&lt;/CODE&gt; also check &lt;CODE&gt;splunkd.log&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 11:52:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Roll-Hot-Bucket-into-warm-Error/m-p/174843#M5188</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-01-07T11:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: Roll Hot Bucket into warm-Error</title>
      <link>https://community.splunk.com/t5/Security/Roll-Hot-Bucket-into-warm-Error/m-p/174844#M5189</link>
      <description>&lt;P&gt;Hi Michael,&lt;/P&gt;

&lt;P&gt;Splunk is running and working fine. I am not able to get relevant logs in splunkd.&lt;/P&gt;

&lt;P&gt;PS: I am searching the logs in C:\ Program Files\ Splunk\ var\ log\ splunk\ splunkd location. Correct me if I am wrong.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Rajul&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 12:39:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Roll-Hot-Bucket-into-warm-Error/m-p/174844#M5189</guid>
      <dc:creator>rajuljain1990</dc:creator>
      <dc:date>2015-01-07T12:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: Roll Hot Bucket into warm-Error</title>
      <link>https://community.splunk.com/t5/Security/Roll-Hot-Bucket-into-warm-Error/m-p/174845#M5190</link>
      <description>&lt;P&gt;Okay, may I ask why you want to do this? If you do it because you want to backup see the docs &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Backupindexeddata"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Backupindexeddata&lt;/A&gt; and most important this part of it:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Important: It is ordinarily not advisable to roll hot buckets manually, as each forced roll permanently decreases search performance over the data. As a general rule, larger buckets are more efficient to search. By prematurely rolling buckets, you're producing smaller, less efficient buckets. In cases where hot data needs to be backed up, a snapshot backup is the preferred method.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What happens if you try to roll the &lt;CODE&gt;_internal&lt;/CODE&gt; index like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk _internal call /data/indexes/_internal/roll-hot-buckets -auth admin:changeme
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 07 Jan 2015 12:46:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Roll-Hot-Bucket-into-warm-Error/m-p/174845#M5190</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-01-07T12:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: Roll Hot Bucket into warm-Error</title>
      <link>https://community.splunk.com/t5/Security/Roll-Hot-Bucket-into-warm-Error/m-p/174846#M5191</link>
      <description>&lt;P&gt;Which version of Splunk you are using?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 12:59:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Roll-Hot-Bucket-into-warm-Error/m-p/174846#M5191</guid>
      <dc:creator>abacus_machine_</dc:creator>
      <dc:date>2015-01-07T12:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: Roll Hot Bucket into warm-Error</title>
      <link>https://community.splunk.com/t5/Security/Roll-Hot-Bucket-into-warm-Error/m-p/174847#M5192</link>
      <description>&lt;P&gt;Hi Michael,&lt;BR /&gt;
I want to do this for R &amp;amp; D purpose. It is my home lab not the critical servers. &lt;/P&gt;

&lt;P&gt;I tried it for the index "_internal", it is throwing the same error:&lt;/P&gt;

&lt;P&gt;C:\Program Files\Splunk\bin&amp;gt;splunk _internal call /data/indexes/_internal/roll-h&lt;BR /&gt;
ot-buckets -auth admin:changeme&lt;BR /&gt;
QUERYING: '&lt;A href="https://127.0.0.1:8089/services/data/indexes/_internal/roll-hot-bucke" target="_blank"&gt;https://127.0.0.1:8089/services/data/indexes/_internal/roll-hot-bucke&lt;/A&gt;&lt;BR /&gt;
ts'&lt;BR /&gt;
FAILED: 'HTTP/1.1 503 Service Unavailable'&lt;BR /&gt;
Content:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;msg type="ERROR"&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In handler 'indexes': could not queue custom action='roll-hot-buckets' for idx=&lt;BR /&gt;
_internal&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Rajul&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:35:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Roll-Hot-Bucket-into-warm-Error/m-p/174847#M5192</guid>
      <dc:creator>rajuljain1990</dc:creator>
      <dc:date>2020-09-28T18:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: Roll Hot Bucket into warm-Error</title>
      <link>https://community.splunk.com/t5/Security/Roll-Hot-Bucket-into-warm-Error/m-p/174848#M5193</link>
      <description>&lt;P&gt;I am using  Splunk 6.2.0 (build 237341)&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2015 05:30:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Roll-Hot-Bucket-into-warm-Error/m-p/174848#M5193</guid>
      <dc:creator>rajuljain1990</dc:creator>
      <dc:date>2015-01-08T05:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: Roll Hot Bucket into warm-Error</title>
      <link>https://community.splunk.com/t5/Security/Roll-Hot-Bucket-into-warm-Error/m-p/174849#M5194</link>
      <description>&lt;P&gt;I had a similar issue. I found out that I had actually run out of disk space on the RAID where my indexes were stored. That may be something to look into. &lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2016 18:08:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Roll-Hot-Bucket-into-warm-Error/m-p/174849#M5194</guid>
      <dc:creator>melcher</dc:creator>
      <dc:date>2016-09-14T18:08:59Z</dc:date>
    </item>
  </channel>
</rss>

