<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Critical Bucket size and range in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Critical-Bucket-size-and-range/m-p/744135#M118221</link>
    <description>&lt;P&gt;I have the same question&lt;/P&gt;</description>
    <pubDate>Mon, 14 Apr 2025 19:57:19 GMT</pubDate>
    <dc:creator>colbym</dc:creator>
    <dc:date>2025-04-14T19:57:19Z</dc:date>
    <item>
      <title>Critical Bucket size and range</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Critical-Bucket-size-and-range/m-p/674352#M112866</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;I have noticed that the cloud monitoring console is reporting a critical bucket. I only have one and have attached a screenshot. The small % is 100.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, I am not certain as to what this really means and whether it is something to worry about or not.&lt;/P&gt;&lt;P&gt;Any help would be appreciated,&lt;/P&gt;&lt;P&gt;Jamie&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 10:24:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Critical-Bucket-size-and-range/m-p/674352#M112866</guid>
      <dc:creator>jamie1</dc:creator>
      <dc:date>2024-01-16T10:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: Critical Bucket size and range</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Critical-Bucket-size-and-range/m-p/744135#M118221</link>
      <description>&lt;P&gt;I have the same question&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 19:57:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Critical-Bucket-size-and-range/m-p/744135#M118221</guid>
      <dc:creator>colbym</dc:creator>
      <dc:date>2025-04-14T19:57:19Z</dc:date>
    </item>
    <item>
      <title>Re: Critical Bucket size and range</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Critical-Bucket-size-and-range/m-p/744136#M118222</link>
      <description>&lt;P&gt;This is an indication of inefficient bucket use, meaning buckets roll `before they fill up.&amp;nbsp; This can happen when indexers restart often, but in this case I suspect it's just a matter of the main index getting very few events before &lt;FONT face="courier new,courier"&gt;maxHotSpecSecs&lt;/FONT&gt; is reached and the bucket rolls to warm.&lt;/P&gt;&lt;P&gt;The answer for buckets that are known to contain few events is to set &lt;FONT face="courier new,courier"&gt;maxDataSize&lt;/FONT&gt; to a value that makes the bucket at least 50% full before it rolls.&amp;nbsp; The default bucket size is 750MB.&amp;nbsp; The &lt;FONT face="courier new,courier"&gt;dbinspect&lt;/FONT&gt; command can tell you the current size of buckets to give you an idea of how to set &lt;FONT face="courier new,courier"&gt;maxDataSize&lt;/FONT&gt;.&lt;/P&gt;&lt;P&gt;Best Practice is to not use the main index at all.&amp;nbsp; All incoming data should go into a custom index, leaving main empty (and not needing to roll).&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 20:42:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Critical-Bucket-size-and-range/m-p/744136#M118222</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-04-14T20:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Critical Bucket size and range</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Critical-Bucket-size-and-range/m-p/744216#M118236</link>
      <description>Another reason could be that your events contains timestamps from very far away each other. This also leads that buckets will close earlier than those are full.&lt;BR /&gt;&lt;BR /&gt;There should be some indications for reason in _internal logs or even some CMC -&amp;gt; Indexing -&amp;gt; Data quality.</description>
      <pubDate>Tue, 15 Apr 2025 20:45:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Critical-Bucket-size-and-range/m-p/744216#M118236</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-04-15T20:45:40Z</dc:date>
    </item>
  </channel>
</rss>

