<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does Splunk recognize when buckets are deleted? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Does-Splunk-recognize-when-buckets-are-deleted/m-p/281799#M10687</link>
    <description>&lt;P&gt;Splunk will perform bucket fixups periodically and find the bucket no longer exists.  At which time it will log a message or two or three and then remove the bucket from the manifest.&lt;/P&gt;

&lt;P&gt;See &lt;CODE&gt;index=_internal log_level=warn* OR log_level=err*&lt;/CODE&gt;.  The events should occur in less than 24 hours after the manual removal.  Searches will just have "holes" in the data if a searchable copy of the bucket doesnt exist.&lt;/P&gt;</description>
    <pubDate>Mon, 06 Jun 2016 14:59:40 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2016-06-06T14:59:40Z</dc:date>
    <item>
      <title>Does Splunk recognize when buckets are deleted?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Does-Splunk-recognize-when-buckets-are-deleted/m-p/281798#M10686</link>
      <description>&lt;P&gt;I am doing a simple recovery test and deleted some warm buckets, but Splunk doesn't seem to even realize anything is wrong.  Is this normal?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2016 14:56:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Does-Splunk-recognize-when-buckets-are-deleted/m-p/281798#M10686</guid>
      <dc:creator>lycollicott</dc:creator>
      <dc:date>2016-06-06T14:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk recognize when buckets are deleted?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Does-Splunk-recognize-when-buckets-are-deleted/m-p/281799#M10687</link>
      <description>&lt;P&gt;Splunk will perform bucket fixups periodically and find the bucket no longer exists.  At which time it will log a message or two or three and then remove the bucket from the manifest.&lt;/P&gt;

&lt;P&gt;See &lt;CODE&gt;index=_internal log_level=warn* OR log_level=err*&lt;/CODE&gt;.  The events should occur in less than 24 hours after the manual removal.  Searches will just have "holes" in the data if a searchable copy of the bucket doesnt exist.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2016 14:59:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Does-Splunk-recognize-when-buckets-are-deleted/m-p/281799#M10687</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-06-06T14:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk recognize when buckets are deleted?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Does-Splunk-recognize-when-buckets-are-deleted/m-p/281800#M10688</link>
      <description>&lt;P&gt;That search was the first thing I checked, but it had nothing about these buckets.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2016 16:27:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Does-Splunk-recognize-when-buckets-are-deleted/m-p/281800#M10688</guid>
      <dc:creator>lycollicott</dc:creator>
      <dc:date>2016-06-06T16:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk recognize when buckets are deleted?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Does-Splunk-recognize-when-buckets-are-deleted/m-p/281801#M10689</link>
      <description>&lt;P&gt;Probably has to with the log verbosity on BucketMover or something.  I'd file a low priority ticket with support if you're THAT interested.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2016 16:31:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Does-Splunk-recognize-when-buckets-are-deleted/m-p/281801#M10689</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-06-06T16:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk recognize when buckets are deleted?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Does-Splunk-recognize-when-buckets-are-deleted/m-p/281802#M10690</link>
      <description>&lt;P&gt;What does |dbinspect index= return for these buckets? Splunk should eventually log an error message since there should be metadata associated with the deleted buckets, but you will have data gaps since the raw data is deleted.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2016 17:46:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Does-Splunk-recognize-when-buckets-are-deleted/m-p/281802#M10690</guid>
      <dc:creator>splunk_force_as</dc:creator>
      <dc:date>2016-06-06T17:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk recognize when buckets are deleted?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Does-Splunk-recognize-when-buckets-are-deleted/m-p/281803#M10691</link>
      <description>&lt;P&gt;I deleted bucket ids 32-34 and 37-39 and dbinspect only shows results for 35-36, so it is still unaware that anything is missing.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2016 17:58:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Does-Splunk-recognize-when-buckets-are-deleted/m-p/281803#M10691</guid>
      <dc:creator>lycollicott</dc:creator>
      <dc:date>2016-06-06T17:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk recognize when buckets are deleted?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Does-Splunk-recognize-when-buckets-are-deleted/m-p/281804#M10692</link>
      <description>&lt;P&gt;From Splunk Support:&lt;/P&gt;

&lt;P&gt;"Splunk assumes that you are doing this on-purpose and therefore would not send any WARN/ERROR events.&lt;/P&gt;

&lt;P&gt;The only reason you would alert is if a bucket were corrupt or never made it.   Once it was there and you deleted it, from Splunk's perspective, everything was functioning."&lt;/P&gt;

&lt;P&gt;That doesn't seem like a sound process to me, but that's the explanation thus far.  &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;UPDATE&lt;/STRONG&gt; June 14: I've done some more testing and I just can't accept the outcome.  Splunk is essentially a database and as an old &lt;BR /&gt;
Oracle DBA I would expect/assume that it has some self-awareness of its integrity.  I'm going to ask for this to be considered a defect.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;UPDATE&lt;/STRONG&gt; June 30: Support is going to perform some testing and submit an enhancement request.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;UPDATE&lt;/STRONG&gt; July 06: Support submitted enhancement request SPL-123789&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 19:29:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Does-Splunk-recognize-when-buckets-are-deleted/m-p/281804#M10692</guid>
      <dc:creator>lycollicott</dc:creator>
      <dc:date>2016-06-07T19:29:50Z</dc:date>
    </item>
  </channel>
</rss>

