<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cluster Index Bucket Stuck as &amp;quot;In Flight&amp;quot; - Roll, Resync and Delete Fails (Status=PendingDiscard) in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/546835#M5523</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233194"&gt;@richardgosnay&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You should rename those buckets by removing &lt;STRONG&gt;inflight-&lt;/STRONG&gt; in front of the bucket name.&lt;/P&gt;&lt;DIV&gt;1- Put the CM in maintenance mode&lt;/DIV&gt;&lt;DIV&gt;2- Issue ./splunk offline on the IDX where the inflight bucket is located. .&lt;/DIV&gt;&lt;DIV&gt;3- Rename the inflight bucket to a normal bucket.&lt;/DIV&gt;&lt;DIV&gt;4- Turn back up the IDX with ./splunk start&lt;/DIV&gt;&lt;DIV&gt;5- Remove the maintenance mode on the CM.&lt;/DIV&gt;&lt;DIV&gt;6- After this, Splunk will replicate the bucket and move it to the coldPath&lt;/DIV&gt;</description>
    <pubDate>Tue, 06 Apr 2021 10:17:47 GMT</pubDate>
    <dc:creator>scelikok</dc:creator>
    <dc:date>2021-04-06T10:17:47Z</dc:date>
    <item>
      <title>Cluster Index Bucket Stuck as "In Flight" - Roll, Resync and Delete Fails (Status=PendingDiscard)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/546831#M5521</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently running Splunk 7.3.0 and have 32 indexes running in a single cluster with 2 peers.&lt;/P&gt;&lt;P&gt;Indexes are being replicated across both peers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything was working fine until we experienced a network blip 12 days ago, now I've noticed that the Replication Factor is not being met because there are some buckets from this time period which don't match, an average of about 3 buckets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried to Roll, Resync and Delete these buckets via the GUI but each step fails.&amp;nbsp; When I check splunkd.log, it appears as if Splunk is automatically trying to recover from these Fix Up tasks but it keeps reporting that the bucket is still in flight so can't.&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;04-06-2021 08:07:39.618 +0100 INFO CMSlave - truncate request bid=bel1_qa_apps~19028~25359C10-2544-436D-893A-657C950D7863 bytes=0x0 current bid status=Complete&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;04-06-2021 08:07:39.618 +0100 INFO CMSlave - bid=bel1_qa_apps~19028~25359C10-2544-436D-893A-657C950D7863 Transitioning status from=Complete to=PendingDiscard for reason="schedule delete bucket"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;04-06-2021 08:07:39.618 +0100 WARN CMSlave - event=scheduleDeleteBucket, bid=bel1_qa_apps~19028~25359C10-2544-436D-893A-657C950D7863 bucket already in flight&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;04-06-2021 08:07:39.618 +0100 ERROR CMSlave - event=scheduleDeleteBucket, bid=bel1_qa_apps~19028~25359C10-2544-436D-893A-657C950D7863 bucket already in flight&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;04-06-2021 08:07:39.618 +0100 INFO CMSlave - bid=bel1_qa_apps~19028~25359C10-2544-436D-893A-657C950D7863 Transitioning status from=PendingDiscard to=Complete for reason="failed to schedule delete bucket"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;04-06-2021 08:07:39.618 +0100 ERROR ClusterSlaveBucketHandler - truncate bid=bel1_qa_apps~19028~25359C10-2544-436D-893A-657C950D7863 bytes=0x0 earliest=0 latest=0 err='bucket already in flight'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;04-06-2021 08:07:39.618 +0100 INFO CMSlave - truncate request bid=bel1_qa_apps~19090~25359C10-2544-436D-893A-657C950D7863 bytes=0x0 current bid status=Complete&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;04-06-2021 08:07:39.619 +0100 INFO CMSlave - bid=bel1_qa_apps~19090~25359C10-2544-436D-893A-657C950D7863 Transitioning status from=Complete to=PendingDiscard for reason="schedule delete bucket"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;04-06-2021 08:07:39.619 +0100 WARN CMSlave - event=scheduleDeleteBucket, bid=bel1_qa_apps~19090~25359C10-2544-436D-893A-657C950D7863 &lt;STRONG&gt;bucket already in flight&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;04-06-2021 08:07:39.619 +0100 ERROR CMSlave - event=scheduleDeleteBucket, bid=bel1_qa_apps~19090~25359C10-2544-436D-893A-657C950D7863 &lt;STRONG&gt;bucket already in flight&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;04-06-2021 08:07:39.619 +0100 INFO CMSlave - bid=bel1_qa_apps~19090~25359C10-2544-436D-893A-657C950D7863 Transitioning status from=PendingDiscard to=Complete for reason="failed to schedule delete bucket"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;04-06-2021 08:07:39.619 +0100 ERROR ClusterSlaveBucketHandler - truncate bid=bel1_qa_apps~19090~25359C10-2544-436D-893A-657C950D7863 bytes=0x0 earliest=0 latest=0 err='bucket already in flight'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;04-06-2021 08:07:39.620 +0100 INFO CMSlave - Received resync bucket request for bid=bel1_qa_apps~19028~25359C10-2544-436D-893A-657C950D7863 bucketExists=1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;04-06-2021 08:07:39.620 +0100 INFO CMSlave - Received resync bucket request for bid=bel1_qa_apps~19090~25359C10-2544-436D-893A-657C950D7863 bucketExists=1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Because of this, the Generation ID is also increasing quite rapidly.&amp;nbsp; The status for all the buckets in question is stuck on 'PendingDiscard'.&lt;/P&gt;&lt;P&gt;The same messages are appearing on the second node but with different bucket IDs.&amp;nbsp; The same ID's keep repeating every few seconds on both peers.&lt;/P&gt;&lt;P&gt;Should I restart each peer one at a time in hope that the bucket status is released and the fix up jobs can run as normal?&lt;BR /&gt;Do I need to restart the cluster master?&lt;/P&gt;&lt;P&gt;Any advice is appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 09:47:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/546831#M5521</guid>
      <dc:creator>richardgosnay</dc:creator>
      <dc:date>2021-04-06T09:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Index Bucket Stuck as "In Flight" - Roll, Resync and Delete Fails (Status=PendingDiscard)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/546833#M5522</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233194"&gt;@richardgosnay&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you receive some error from the splunk platform?&lt;/P&gt;&lt;P&gt;if yes, can you show me the error?&lt;/P&gt;&lt;P&gt;last question are you sure the buckets ID are not duplicated?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 10:12:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/546833#M5522</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-04-06T10:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Index Bucket Stuck as "In Flight" - Roll, Resync and Delete Fails (Status=PendingDiscard)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/546835#M5523</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233194"&gt;@richardgosnay&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You should rename those buckets by removing &lt;STRONG&gt;inflight-&lt;/STRONG&gt; in front of the bucket name.&lt;/P&gt;&lt;DIV&gt;1- Put the CM in maintenance mode&lt;/DIV&gt;&lt;DIV&gt;2- Issue ./splunk offline on the IDX where the inflight bucket is located. .&lt;/DIV&gt;&lt;DIV&gt;3- Rename the inflight bucket to a normal bucket.&lt;/DIV&gt;&lt;DIV&gt;4- Turn back up the IDX with ./splunk start&lt;/DIV&gt;&lt;DIV&gt;5- Remove the maintenance mode on the CM.&lt;/DIV&gt;&lt;DIV&gt;6- After this, Splunk will replicate the bucket and move it to the coldPath&lt;/DIV&gt;</description>
      <pubDate>Tue, 06 Apr 2021 10:17:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/546835#M5523</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-04-06T10:17:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Index Bucket Stuck as "In Flight" - Roll, Resync and Delete Fails (Status=PendingDiscard)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/546838#M5524</link>
      <description>&lt;P&gt;If I manually locate the buckets in question, they don't have &lt;STRONG&gt;inflight-&lt;/STRONG&gt; in the filename, they appear as normal buckets.&amp;nbsp; But every time I try to run a fix up task like Roll, Resync or Delete, the log files states it is in flight (see previous log snippet).&lt;/P&gt;&lt;P&gt;Should I try running the fix up tasks in maintenance mode?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 10:22:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/546838#M5524</guid>
      <dc:creator>richardgosnay</dc:creator>
      <dc:date>2021-04-06T10:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Index Bucket Stuck as "In Flight" - Roll, Resync and Delete Fails (Status=PendingDiscard)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/546839#M5525</link>
      <description>&lt;P&gt;The only errors in Splunk are the same as the ones in the splunkd.log file, you can see the snippet in the original post.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 10:23:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/546839#M5525</guid>
      <dc:creator>richardgosnay</dc:creator>
      <dc:date>2021-04-06T10:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Index Bucket Stuck as "In Flight" - Roll, Resync and Delete Fails (Status=PendingDiscard)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/546970#M5536</link>
      <description>&lt;P&gt;It seems, the only buckets affected are the replicated ones (rb instead of db).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I manually removed these before restarting the Cluster Master (and peers) will they just be re-created?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 06:43:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/546970#M5536</guid>
      <dc:creator>richardgosnay</dc:creator>
      <dc:date>2021-04-07T06:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Index Bucket Stuck as "In Flight" - Roll, Resync and Delete Fails (Status=PendingDiscard)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/546992#M5538</link>
      <description>&lt;P&gt;You must be sure that those buckets are not the only one inside the cluster. Make sure there is another bucket with the same name "rb" or "db" before deleting. Yes Cluster Master will make them replicated after restart the particular peer.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 09:15:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/546992#M5538</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-04-07T09:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Index Bucket Stuck as "In Flight" - Roll, Resync and Delete Fails (Status=PendingDiscard)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/547006#M5540</link>
      <description>&lt;P&gt;The bucket ID is the same, but the range at the beginning is not.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Example&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Bucket ID:&amp;nbsp;&lt;SPAN&gt;_audit~110~25359C10-2544-436D-893A-657C950D7863&lt;BR /&gt;Peer 1 Folder Name:&amp;nbsp;rb_1614134403_1612300619_110_25359C10-2544-436D-893A-657C950D7863&lt;BR /&gt;Peer 2 Folder Name:&amp;nbsp;db_1614134587_1612300619_110_25359C10-2544-436D-893A-657C950D7863&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;All neighbouring folder names match perfectly, it's only the buckets in question that don't match.&amp;nbsp; If I remove the RB folder, will it get re-created with the correct DB equivalent?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 10:12:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/547006#M5540</guid>
      <dc:creator>richardgosnay</dc:creator>
      <dc:date>2021-04-07T10:12:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Index Bucket Stuck as "In Flight" - Roll, Resync and Delete Fails (Status=PendingDiscard)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/547013#M5541</link>
      <description>&lt;P&gt;Since db names one has wider time-range it seems safe to delete rb bucket. It will be created on peer restart.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 11:03:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/547013#M5541</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-04-07T11:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Index Bucket Stuck as "In Flight" - Roll, Resync and Delete Fails (Status=PendingDiscard)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/547014#M5542</link>
      <description>&lt;P&gt;Thank you greatly, I will be performing the peer restarts in around 7 hours time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll let you know if it works and upvote accordingly.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 11:50:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/547014#M5542</guid>
      <dc:creator>richardgosnay</dc:creator>
      <dc:date>2021-04-07T11:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Index Bucket Stuck as "In Flight" - Roll, Resync and Delete Fails (Status=PendingDiscard)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/547121#M5546</link>
      <description>&lt;P&gt;That worked perfectly, thank you...&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 22:09:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cluster-Index-Bucket-Stuck-as-quot-In-Flight-quot-Roll-Resync/m-p/547121#M5546</guid>
      <dc:creator>richardgosnay</dc:creator>
      <dc:date>2021-04-07T22:09:33Z</dc:date>
    </item>
  </channel>
</rss>

