<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multisite Indexer Cluster Inconsistent Buckets: How to delete buckets and their metadata to no longer be listed in the cluster master REST endpoint? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Multisite-Indexer-Cluster-Inconsistent-Buckets-How-to-delete/m-p/272230#M10359</link>
    <description>&lt;PRE&gt;&lt;CODE&gt;10-15-2015 13:48:43.465 +0200 INFO CMPeer - peer=7EBE2435-3FB3-4CE2-85E3-35931CD26293 peer_name=zhhapssp-slin05.it.bwns.ch bid=_internal~11942~14EE1C69-1AED-4A51-8A8E-0FDCBE2C16FC transitioning from=Unsearchable to=PendingSearchable oldmask=0x0 newmask=0x0 reason="fixup searchable count"
10-15-2015 13:42:08.936 +0200 INFO CMPeer - peer=DF9EF4CB-14CE-4F5B-8BA0-9D687671B4B6 peer_name=oltapssp-slin02.it.bwns.ch bid=_internal~11942~14EE1C69-1AED-4A51-8A8E-0FDCBE2C16FC transitioning from=Unsearchable to=PendingSearchable oldmask=0x0 newmask=0x0 reason="fixup searchable count"
10-15-2015 13:46:07.692 +0200 INFO CMPeer - peer=DF9EF4CB-14CE-4F5B-8BA0-9D687671B4B6 peer_name=oltapssp-slin02.it.bwns.ch bid=_internal~11942~14EE1C69-1AED-4A51-8A8E-0FDCBE2C16FC transitioning from=Unsearchable to=PendingSearchable oldmask=0x0 newmask=0x0 reason="fixup searchable count"
10-15-2015 13:39:28.442 +0200 INFO CMPeer - peer=7EBE2435-3FB3-4CE2-85E3-35931CD26293 peer_name=zhhapssp-slin05.it.bwns.ch bid=_internal~11942~14EE1C69-1AED-4A51-8A8E-0FDCBE2C16FC transitioning from=Unsearchable to=PendingSearchable oldmask=0x0 newmask=0x0 reason="fixup searchable count"
10-15-2015 13:36:19.039 +0200 INFO CMPeer - peer=DF9EF4CB-14CE-4F5B-8BA0-9D687671B4B6 peer_name=oltapssp-slin02.it.bwns.ch bid=_internal~11942~14EE1C69-1AED-4A51-8A8E-0FDCBE2C16FC transitioning from=Unsearchable to=PendingSearchable oldmask=0x0 newmask=0x0 reason="fixup searchable count"
10-15-2015 13:36:00.952 +0200 INFO CMPeer - peer=7EBE2435-3FB3-4CE2-85E3-35931CD26293 peer_name=zhhapssp-slin05.it.bwns.ch bid=_internal~11942~14EE1C69-1AED-4A51-8A8E-0FDCBE2C16FC transitioning from=Unsearchable to=PendingSearchable oldmask=0x0 newmask=0x0 reason="fixup searchable count"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 15 Oct 2015 12:36:16 GMT</pubDate>
    <dc:creator>tluluma3</dc:creator>
    <dc:date>2015-10-15T12:36:16Z</dc:date>
    <item>
      <title>Multisite Indexer Cluster Inconsistent Buckets: How to delete buckets and their metadata to no longer be listed in the cluster master REST endpoint?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Multisite-Indexer-Cluster-Inconsistent-Buckets-How-to-delete/m-p/272227#M10356</link>
      <description>&lt;P&gt;Every time when I do a &lt;CODE&gt;splunk rolling-restart cluster-Peers&lt;/CODE&gt; I have some buckets that are listed in the REST Endpoint, but they are not on the filesystem on the particular Indexer.&lt;BR /&gt;
I can find these buckets with:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal host="CLUSTERMASTER" sourcetype=splunkd from=Unsearchable | stats values(peer_name) by bid
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I then can delete the buckets with &lt;CODE&gt;splunk _internal call /services/cluster/master/buckets/BID/remove_all -method POST&lt;/CODE&gt;, but they reappear after the next rolling restart.&lt;/P&gt;

&lt;P&gt;Is there a way to delete the metadata from these buckets for the Cluster master to "forget" them forever?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 10:15:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Multisite-Indexer-Cluster-Inconsistent-Buckets-How-to-delete/m-p/272227#M10356</guid>
      <dc:creator>tluluma3</dc:creator>
      <dc:date>2015-10-14T10:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: Multisite Indexer Cluster Inconsistent Buckets: How to delete buckets and their metadata to no longer be listed in the cluster master REST endpoint?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Multisite-Indexer-Cluster-Inconsistent-Buckets-How-to-delete/m-p/272228#M10357</link>
      <description>&lt;P&gt;can you post the logs for a specific bucket ?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 17:58:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Multisite-Indexer-Cluster-Inconsistent-Buckets-How-to-delete/m-p/272228#M10357</guid>
      <dc:creator>dxu_splunk</dc:creator>
      <dc:date>2015-10-14T17:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Multisite Indexer Cluster Inconsistent Buckets: How to delete buckets and their metadata to no longer be listed in the cluster master REST endpoint?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Multisite-Indexer-Cluster-Inconsistent-Buckets-How-to-delete/m-p/272229#M10358</link>
      <description>&lt;P&gt;seems like you want to delete a bucket entirely.&lt;/P&gt;

&lt;P&gt;if remove_all doesn't work (it might not work if the bucket is in some transitory state, ie PendingSearchable), you can try freezing the bucket on the indexers.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;curl -k -u USER:PASS https://indexer:mgmt_port/services/data/indexes/INDEX/freeze-buckets -d bucket_ids=117_22220097-5E3F-4D26-B301-ECE3C4CD2222 -X POST
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;bucket_ids is a list of buckets by ID_GUID. this should remove the bucket on that specific indexer - just repeat for all the other copies of the bucket&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:34:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Multisite-Indexer-Cluster-Inconsistent-Buckets-How-to-delete/m-p/272229#M10358</guid>
      <dc:creator>dxu_splunk</dc:creator>
      <dc:date>2020-09-29T07:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: Multisite Indexer Cluster Inconsistent Buckets: How to delete buckets and their metadata to no longer be listed in the cluster master REST endpoint?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Multisite-Indexer-Cluster-Inconsistent-Buckets-How-to-delete/m-p/272230#M10359</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;10-15-2015 13:48:43.465 +0200 INFO CMPeer - peer=7EBE2435-3FB3-4CE2-85E3-35931CD26293 peer_name=zhhapssp-slin05.it.bwns.ch bid=_internal~11942~14EE1C69-1AED-4A51-8A8E-0FDCBE2C16FC transitioning from=Unsearchable to=PendingSearchable oldmask=0x0 newmask=0x0 reason="fixup searchable count"
10-15-2015 13:42:08.936 +0200 INFO CMPeer - peer=DF9EF4CB-14CE-4F5B-8BA0-9D687671B4B6 peer_name=oltapssp-slin02.it.bwns.ch bid=_internal~11942~14EE1C69-1AED-4A51-8A8E-0FDCBE2C16FC transitioning from=Unsearchable to=PendingSearchable oldmask=0x0 newmask=0x0 reason="fixup searchable count"
10-15-2015 13:46:07.692 +0200 INFO CMPeer - peer=DF9EF4CB-14CE-4F5B-8BA0-9D687671B4B6 peer_name=oltapssp-slin02.it.bwns.ch bid=_internal~11942~14EE1C69-1AED-4A51-8A8E-0FDCBE2C16FC transitioning from=Unsearchable to=PendingSearchable oldmask=0x0 newmask=0x0 reason="fixup searchable count"
10-15-2015 13:39:28.442 +0200 INFO CMPeer - peer=7EBE2435-3FB3-4CE2-85E3-35931CD26293 peer_name=zhhapssp-slin05.it.bwns.ch bid=_internal~11942~14EE1C69-1AED-4A51-8A8E-0FDCBE2C16FC transitioning from=Unsearchable to=PendingSearchable oldmask=0x0 newmask=0x0 reason="fixup searchable count"
10-15-2015 13:36:19.039 +0200 INFO CMPeer - peer=DF9EF4CB-14CE-4F5B-8BA0-9D687671B4B6 peer_name=oltapssp-slin02.it.bwns.ch bid=_internal~11942~14EE1C69-1AED-4A51-8A8E-0FDCBE2C16FC transitioning from=Unsearchable to=PendingSearchable oldmask=0x0 newmask=0x0 reason="fixup searchable count"
10-15-2015 13:36:00.952 +0200 INFO CMPeer - peer=7EBE2435-3FB3-4CE2-85E3-35931CD26293 peer_name=zhhapssp-slin05.it.bwns.ch bid=_internal~11942~14EE1C69-1AED-4A51-8A8E-0FDCBE2C16FC transitioning from=Unsearchable to=PendingSearchable oldmask=0x0 newmask=0x0 reason="fixup searchable count"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 15 Oct 2015 12:36:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Multisite-Indexer-Cluster-Inconsistent-Buckets-How-to-delete/m-p/272230#M10359</guid>
      <dc:creator>tluluma3</dc:creator>
      <dc:date>2015-10-15T12:36:16Z</dc:date>
    </item>
  </channel>
</rss>

