<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Handle lost buckets in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468104#M80601</link>
    <description>&lt;P&gt;I have splunk cluster with sf=2, rf=2 (they are met).&lt;BR /&gt;
It was maintained by another contractor, so I have no ideas about what caused the issue.&lt;BR /&gt;
First, on master node for some indexes I see data copies marked grey and data copies number is 170/173, etc... same for serachable and replicated copies. And no bucket fixup tasks are running.&lt;BR /&gt;
I guess this means that some buckets do not exist on both indexers, am I right?&lt;/P&gt;

&lt;P&gt;Second, I ran dbinspect command for this index, it returned 173 results. tsidxState is "full" for every bucket.&lt;/P&gt;

&lt;P&gt;How do I find problematic buckets and delete them to make Indexer clustering page green again?&lt;/P&gt;

&lt;P&gt;UPD. I uploaded photo&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7853i0C327D56BF574EB9/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Oct 2019 08:09:57 GMT</pubDate>
    <dc:creator>asnegina</dc:creator>
    <dc:date>2019-10-30T08:09:57Z</dc:date>
    <item>
      <title>Handle lost buckets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468104#M80601</link>
      <description>&lt;P&gt;I have splunk cluster with sf=2, rf=2 (they are met).&lt;BR /&gt;
It was maintained by another contractor, so I have no ideas about what caused the issue.&lt;BR /&gt;
First, on master node for some indexes I see data copies marked grey and data copies number is 170/173, etc... same for serachable and replicated copies. And no bucket fixup tasks are running.&lt;BR /&gt;
I guess this means that some buckets do not exist on both indexers, am I right?&lt;/P&gt;

&lt;P&gt;Second, I ran dbinspect command for this index, it returned 173 results. tsidxState is "full" for every bucket.&lt;/P&gt;

&lt;P&gt;How do I find problematic buckets and delete them to make Indexer clustering page green again?&lt;/P&gt;

&lt;P&gt;UPD. I uploaded photo&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7853i0C327D56BF574EB9/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 08:09:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468104#M80601</guid>
      <dc:creator>asnegina</dc:creator>
      <dc:date>2019-10-30T08:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: Handle lost buckets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468105#M80602</link>
      <description>&lt;P&gt;Have you tried to restart splunk on Cluster Master? Sometimes I have seen that CM flags indexes with grey color but on top of the screen it displays Search Factor and Replication Factor are met &amp;amp; after few minutes every indexes were green.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 09:27:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468105#M80602</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-10-30T09:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: Handle lost buckets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468106#M80603</link>
      <description>&lt;P&gt;I tried, but it does not help. All blocks for particular indexes are constantly grey. You can check the photo I added to my question (can't make screenshot, sorry)&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 10:04:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468106#M80603</guid>
      <dc:creator>asnegina</dc:creator>
      <dc:date>2019-10-30T10:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: Handle lost buckets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468107#M80604</link>
      <description>&lt;P&gt;If you click on that grey icon for one of the index, it will take you to Bucket Status page, as you mentioned you don't have any bucket fixup running but can you please check any fixup tasks - pending ?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 11:12:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468107#M80604</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-10-30T11:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: Handle lost buckets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468108#M80605</link>
      <description>&lt;P&gt;I was incorrect, actually I have no fixup tasks at all (pending or in progress), and no excess buckets btw&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 11:56:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468108#M80605</guid>
      <dc:creator>asnegina</dc:creator>
      <dc:date>2019-10-30T11:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Handle lost buckets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468109#M80606</link>
      <description>&lt;P&gt;try to fix the bucket editing the gray ones :&lt;/P&gt;

&lt;P&gt;For buckets that have been stuck in fixup for long periods of time, you can take remedial action.&lt;/P&gt;

&lt;P&gt;Click Action for the bucket that you want to manage.&lt;BR /&gt;
Select one of the available actions:&lt;BR /&gt;
View bucket details&lt;BR /&gt;
Roll&lt;BR /&gt;
Resync&lt;BR /&gt;
Delete Copy&lt;BR /&gt;
A pop-up window appears to guide you through the selected action.&lt;BR /&gt;
Use the following sequence when performing actions on anomalous bucket.&lt;/P&gt;

&lt;P&gt;View bucket details&lt;BR /&gt;
Roll&lt;BR /&gt;
Resync&lt;BR /&gt;
Delete Copy&lt;BR /&gt;
Only perform the next action if the previous one does not resolve the issue.&lt;/P&gt;

&lt;P&gt;For further information, check this link -&amp;gt; &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.0/Indexer/Anomalousbuckets#Take_action_on_an_anomalous_bucket"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.0/Indexer/Anomalousbuckets#Take_action_on_an_anomalous_bucket&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If it did not work, please submit a case to splunk support and generate a diag file to attach to the case running ./splunk diag&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2019 06:29:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468109#M80606</guid>
      <dc:creator>ivanreis</dc:creator>
      <dc:date>2019-11-04T06:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: Handle lost buckets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468110#M80607</link>
      <description>&lt;P&gt;Ivan, please post your method as an answer instead of a comment. It will help mark the question as answered.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 21:53:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468110#M80607</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2019-11-13T21:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: Handle lost buckets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468111#M80608</link>
      <description>&lt;P&gt;try to fix the bucket editing the gray ones :&lt;/P&gt;

&lt;P&gt;For buckets that have been stuck in fixup for long periods of time, you can take remedial action.&lt;/P&gt;

&lt;P&gt;Click Action for the bucket that you want to manage.&lt;BR /&gt;
Select one of the available actions:&lt;BR /&gt;
View bucket details&lt;BR /&gt;
Roll&lt;BR /&gt;
Resync&lt;BR /&gt;
Delete Copy&lt;BR /&gt;
A pop-up window appears to guide you through the selected action.&lt;BR /&gt;
Use the following sequence when performing actions on anomalous bucket.&lt;/P&gt;

&lt;P&gt;View bucket details&lt;BR /&gt;
Roll&lt;BR /&gt;
Resync&lt;BR /&gt;
Delete Copy&lt;BR /&gt;
Only perform the next action if the previous one does not resolve the issue.&lt;/P&gt;

&lt;P&gt;For further information, check this link -&amp;gt; &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.0/Indexer/Anomalousbuckets#Take_action_on_an_anomalous_bucket"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.0/Indexer/Anomalousbuckets#Take_action_on_an_anomalous_bucket&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If it did not work, please submit a case to splunk support and generate a diag file to attach to the case running ./splunk diag&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 23:56:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468111#M80608</guid>
      <dc:creator>ivanreis</dc:creator>
      <dc:date>2019-11-13T23:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: Handle lost buckets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468112#M80609</link>
      <description>&lt;P&gt;Thank you for your answer. As I mentioned before I have no buckets in fixup state when I click on gray ones. Now it looks like a visual bug but it still persists after server restart.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 15:38:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Handle-lost-buckets/m-p/468112#M80609</guid>
      <dc:creator>asnegina</dc:creator>
      <dc:date>2019-11-14T15:38:29Z</dc:date>
    </item>
  </channel>
</rss>

