<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BucketMover Errors in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/BucketMover-Errors/m-p/138863#M28531</link>
    <description>&lt;P&gt;Buckets were rolling too often from warm to cold.  We were trying to get too fancy on out settings.  Only needed FrozenTimePeriodInSecs = 259200, not maxWarmDBCount, not MaxHotSpacSecs.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Dec 2013 13:29:06 GMT</pubDate>
    <dc:creator>rmorlen</dc:creator>
    <dc:date>2013-12-12T13:29:06Z</dc:date>
    <item>
      <title>BucketMover Errors</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/BucketMover-Errors/m-p/138861#M28529</link>
      <description>&lt;P&gt;We are seeing about 100,000 events per hour with:&lt;/P&gt;

&lt;P&gt;0600 ERROR BucketMover - aborting move because recursive copy from src='/splunkidx/defaultdb/db/db_1384235999_1384149600_72640' to dst='/splunkidx/defaultdb/colddb/inflight-db_1384235999_1384149600_72640' failed (reason='Too many links').&lt;/P&gt;

&lt;P&gt;I realize the "Too many links" message is a Linux issue.  Not sure why it is happening but more importantly how to I stop the error messages?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2013 17:34:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/BucketMover-Errors/m-p/138861#M28529</guid>
      <dc:creator>rmorlen</dc:creator>
      <dc:date>2013-11-12T17:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: BucketMover Errors</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/BucketMover-Errors/m-p/138862#M28530</link>
      <description>&lt;P&gt;What I have found is that there is a Linux limit of 32,000 files in a directory and my colddb directory has hit that limit although we only keep 30 days of data.&lt;/P&gt;

&lt;P&gt;Is there a way to manually cause a roll from cold to frozen?&lt;/P&gt;

&lt;P&gt;Or increase the size of the warm bucket so that it is rolling to cold so often?&lt;/P&gt;

&lt;P&gt;Settings from indexes.conf:&lt;/P&gt;

&lt;P&gt;[main]&lt;BR /&gt;
homePath   = /splunkidx/defaultdb/db&lt;BR /&gt;
coldPath   = /splunkidx/defaultdb/colddb&lt;BR /&gt;
thawedPath = /splunkidx/defaultdb/thaweddb&lt;BR /&gt;
maxDataSize = auto_high_volume&lt;BR /&gt;
maxTotalDataSizeMB = 400000&lt;BR /&gt;
maxHotSpanSecs = 86400&lt;BR /&gt;
frozenTimePeriodInSecs = 2592000&lt;BR /&gt;
maxWarmDBCount = 30&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:15:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/BucketMover-Errors/m-p/138862#M28530</guid>
      <dc:creator>rmorlen</dc:creator>
      <dc:date>2020-09-28T15:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: BucketMover Errors</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/BucketMover-Errors/m-p/138863#M28531</link>
      <description>&lt;P&gt;Buckets were rolling too often from warm to cold.  We were trying to get too fancy on out settings.  Only needed FrozenTimePeriodInSecs = 259200, not maxWarmDBCount, not MaxHotSpacSecs.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2013 13:29:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/BucketMover-Errors/m-p/138863#M28531</guid>
      <dc:creator>rmorlen</dc:creator>
      <dc:date>2013-12-12T13:29:06Z</dc:date>
    </item>
  </channel>
</rss>

