<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The percentage of small of buckets is very high and exceeded the red thresholds...-When the red warning will disappear after fixed parsing? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435719#M85796</link>
    <description>&lt;P&gt;I'm not sure. It seemed to be in the range of 24 hours, but I could never perfectly emulate it.&lt;/P&gt;</description>
    <pubDate>Thu, 28 May 2020 22:02:16 GMT</pubDate>
    <dc:creator>jacobpevans</dc:creator>
    <dc:date>2020-05-28T22:02:16Z</dc:date>
    <item>
      <title>The percentage of small of buckets is very high and exceeded the red thresholds...-When the red warning will disappear after fixed parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435706#M85783</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;I had that red warning right before the username in splunk and after analyzing I found that there were a few sourcetypes with wrong timeparsing.&lt;BR /&gt;I have fixed all of these fails but the red warning is still appearing (there is approximately 1 hours since last parsing error)&lt;BR /&gt;I am curious if there are no anymore parsing errors, when the red warning will disappear?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 23:58:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435706#M85783</guid>
      <dc:creator>net1993</dc:creator>
      <dc:date>2020-06-05T23:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of small of buckets is very high and exceeded the red thresholds...-When the red warning will disappear after fixed parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435707#M85784</link>
      <description>&lt;P&gt;None of you know this?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 09:06:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435707#M85784</guid>
      <dc:creator>net1993</dc:creator>
      <dc:date>2019-08-09T09:06:31Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of small of buckets is very high and exceeded the red thresholds...-When the red warning will disappear after fixed parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435708#M85785</link>
      <description>&lt;P&gt;I have also checked that actually, there are no high number of hot buckets neither there have been in the past. There are only 3 hot buckets which should be normal. &lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 11:01:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435708#M85785</guid>
      <dc:creator>net1993</dc:creator>
      <dc:date>2019-08-09T11:01:59Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of small of buckets is very high and exceeded the red thresholds...-When the red warning will disappear after fixed parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435709#M85786</link>
      <description>&lt;P&gt;Greetings &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/145622"&gt;@net1993&lt;/a&gt;,&lt;/P&gt;

&lt;P&gt;Please post your version. After upgrading to 7.2.4 from 6.6.4, we are seeing the same error. According to &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199795"&gt;@kheo_splunk&lt;/a&gt; on &lt;A href="https://answers.splunk.com/answers/700903/health-warning-the-percentage-of-small-of-buckets.html" target="_blank"&gt;this Splunk answers&lt;/A&gt;, a small bucket is 10% of &lt;CODE&gt;maxDataSize&lt;/CODE&gt; for the index (although I couldn't find that in &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/IndexesConf" target="_blank"&gt;indexes.conf&lt;/A&gt; or &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/HealthConf" target="_blank"&gt;health.conf&lt;/A&gt;). Here's as far as I've gotten with this:&lt;/P&gt;

&lt;H3&gt;Error&lt;/H3&gt;

&lt;P&gt;On an indexer, click the health badge in header bar next to your user name, then &lt;CODE&gt;Buckets&lt;/CODE&gt;.&lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/273506-health-badge.png" alt="health badge" /&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Buckets
Root Cause(s):
The percentage of small of buckets created (83) over the last hour is very high and exceeded the red thresholds (50) for index=windows, and possibly more indexes, on this indexer
Last 50 related messages:
08-16-2019 10:30:21.649 -0400 INFO HotBucketRoller - finished moving hot to warm bid=services~920~0514B976-C45E-486C-B57C-A1E810AEC966 idx=services from=hot_v1_920 to=db_1565890631_1565852558_920_0514B976-C45E-486C-B57C-A1E810AEC966 size=393109504 caller=lru maxHotBuckets=3, count=4 hot buckets,evicting_count=1 LRU hots
08-16-2019 10:00:03.781 -0400 INFO HotBucketRoller - finished moving hot to warm bid=windows~145~0514B976-C45E-486C-B57C-A1E810AEC966 idx=windows from=hot_v1_145 to=db_1565761563_1564808117_145_0514B976-C45E-486C-B57C-A1E810AEC966 size=1052672 caller=lru maxHotBuckets=3, count=4 hot buckets,evicting_count=1 LRU hots
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;We have two indexers. The two indexers have different numbers (83 on Indexer 1, 66 on Indexer 2) and errors so it appears to be checking them separately. As a side note, I do not believe the &lt;CODE&gt;over the last hour&lt;/CODE&gt; part of the error is accurate. The setting to change this is &lt;CODE&gt;indicator:percent_small_buckets_created_last_24h&lt;/CODE&gt; which leads me to believe the search is over the past 24 hours.&lt;/P&gt;

&lt;H3&gt;Queries&lt;/H3&gt;

&lt;P&gt;Run the following search for either yesterday or the previous 24 hours. I haven't narrowed down the exact time frame, but it does seem to be some variation of 24 hours.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal sourcetype=splunkd component=HotBucketRoller "finished moving hot to warm"
| eval bucketSizeMB = round(size / 1024 / 1024, 2)
| table _time splunk_server idx bid bucketSizeMB
| rename idx as index
| join type=left index 
    [ | rest /services/data/indexes count=0
      | rename title as index
      | eval maxDataSize = case (maxDataSize == "auto",             750,
                                 maxDataSize == "auto_high_volume", 10000,
                                 true(),                            maxDataSize)
      | table  index updated currentDBSizeMB homePath.maxDataSizeMB maxDataSize maxHotBuckets maxWarmDBCount ]
| eval bucketSizePercent = round(100*(bucketSizeMB/maxDataSize))
| eval isSmallBucket     = if (bucketSizePercent &amp;lt; 10, 1, 0)
| stats sum(isSmallBucket) as num_small_buckets
        count              as num_total_buckets
        by index splunk_server
| eval  percentSmallBuckets = round(100*(num_small_buckets/num_total_buckets))
| sort  - percentSmallBuckets
| eval isViolation = if (percentSmallBuckets &amp;gt; 30, "Yes", "No")
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Breaking it down,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal sourcetype=splunkd component=HotBucketRoller "finished moving hot to warm"
| eval bucketSizeMB = round(size / 1024 / 1024, 2)
| table _time splunk_server idx bid bucketSizeMB
| rename idx as index
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Get each instance of a hot bucket rolling over to a warm bucket. Rename to "index" for the join to work properly. Has the size of the now warm bucket.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| join type=left index 
    [ | rest /services/data/indexes count=0
      | rename title as index
      | eval maxDataSize = case (maxDataSize == "auto",             750,
                                 maxDataSize == "auto_high_volume", 10000,
                                 true(),                            maxDataSize)
      | table  index updated currentDBSizeMB homePath.maxDataSizeMB maxDataSize maxHotBuckets maxWarmDBCount ]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Join each instance of a rollover event to a rest call to get the maxDataSize for that index. A value of "auto" is 750MB. "auto_high_volume" is 10GB (or 1GB on 32 bit systems). The rest is pretty self-explanatory, but I'll explain a few lines.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| eval bucketSizePercent = round(100*(bucketSizeMB/maxDataSize))
| eval isSmallBucket     = if (bucketSizePercent &amp;lt; 10, 1, 0)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Apparently a small bucket is &amp;lt;10% of the maxDataSize for the index.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| eval isViolation = if (percentSmallBuckets &amp;gt; 30, "Yes", "No")
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The standard setting for a violation is &amp;gt;30%.&lt;/P&gt;

&lt;P&gt;This still does not fully work for me, but I believe the answer is close to this. I tried past 60 minutes (definitely not), past 24 hours, Today, and Yesterday.  None of the values match, although I do see "violations". One thing I did notice is that the numbers displayed in the error (83 and 66 for me) do not seem to change as if this check is not running often (every 4 hours? Once a day?).&lt;/P&gt;

&lt;P&gt;If anyone sees anything wrong, just let me know.&lt;/P&gt;

&lt;P&gt;Edit: fixed one issue. This query is now close enough to accurate for my purposes. It does work to find indexes with a high percent of small buckets, it just doesn't match the numbers that Splunk shows.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:49:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435709#M85786</guid>
      <dc:creator>jacobpevans</dc:creator>
      <dc:date>2020-09-30T01:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of small of buckets is very high and exceeded the red thresholds...-When the red warning will disappear after fixed parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435710#M85787</link>
      <description>&lt;P&gt;Also, here's a query to check your buckets without using the &lt;CODE&gt;_internal&lt;/CODE&gt; log. Watch out for the time selector though - it applies to the "endEpoch" (endTime in my query) field (this is the maximum &lt;CODE&gt;_time&lt;/CODE&gt; of events in the bucket - it has nothing to do with when the bucket rolled over) - not the modTime as I would have expected. Thus, you'd need to give a larger time span, and then filter based on modTime.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| dbinspect index=windows
| search state!=hot
| convert ctime(startEpoch) as startTime
| convert ctime(endEpoch)   as endTime
| eval sizeOnDiskMB=round(sizeOnDiskMB, 2)
| stats values(splunk_server) as splunk_servers
        values(sizeOnDiskMB)  as sizesOnDiskMB
        values(modTime)       as modTimes
    by index id startTime endTime eventCount hostCount sourceTypeCount sourceCount state tsidxState
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you're still stuck, I've added additional information on this answer: &lt;A href="https://answers.splunk.com/answers/725555/what-does-this-message-mean-regarding-the-health-s.html?childToView=766381#answer-766381"&gt;https://answers.splunk.com/answers/725555/what-does-this-message-mean-regarding-the-health-s.html?childToView=766381#answer-766381&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 18:30:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435710#M85787</guid>
      <dc:creator>jacobpevans</dc:creator>
      <dc:date>2019-08-16T18:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of small of buckets is very high and exceeded the red thresholds...-When the red warning will disappear after fixed parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435711#M85788</link>
      <description>&lt;P&gt;Hello @jacobevans &lt;BR /&gt;
Thank you for the extensive comment.&lt;BR /&gt;
I am though a bit unsure what you are trying to say. Do you mean this is splunk bug or you mean that this is correct and there is a problem with some sourcetype?&lt;BR /&gt;
I experience the behaviour on splunk 7.2.6 and I believe the errors started to appear after we upgrader 2-3 months ago from v. 6.6.3&lt;BR /&gt;
I 've just tried the search but I get no results for 24h but only for 7 days so I don't understand why it is stated for the last hour.&lt;BR /&gt;
Also when I run the search for 7 days, all of the result rows are IsViolations:"No"&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 08:29:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435711#M85788</guid>
      <dc:creator>net1993</dc:creator>
      <dc:date>2019-08-26T08:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of small of buckets is very high and exceeded the red thresholds...-When the red warning will disappear after fixed parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435712#M85789</link>
      <description>&lt;P&gt;I added a bit more info to this comment here - it was built off of this one: &lt;A href="https://answers.splunk.com/answers/725555/what-does-this-message-mean-regarding-the-health-s.html#answer-766381"&gt;https://answers.splunk.com/answers/725555/what-does-this-message-mean-regarding-the-health-s.html#answer-766381&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Long story short, I do not think this is a bug. I believe Splunk is making a fairly simple calculation which is probably much better than my query, and that the health indicator was simply not a part of anything in 6x hence why you never noticed it before. I have a few other queries I can throw your way if you're interested. When you say my query showed nothing, was it the first main query in the answer or the dbinspect?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2019 03:06:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435712#M85789</guid>
      <dc:creator>jacobpevans</dc:creator>
      <dc:date>2019-08-27T03:06:51Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of small of buckets is very high and exceeded the red thresholds...-When the red warning will disappear after fixed parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435713#M85790</link>
      <description>&lt;P&gt;sure, give them to me please.&lt;BR /&gt;
Yes, I used the very first query: 19rows. I run it for 7 days back and the results which are comming up have only isViolation=No.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2019 06:14:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435713#M85790</guid>
      <dc:creator>net1993</dc:creator>
      <dc:date>2019-08-27T06:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of small of buckets is very high and exceeded the red thresholds...-When the red warning will disappear after fixed parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435714#M85791</link>
      <description>&lt;P&gt;Variation of dbinspect to sort by the raw bucket size. Remember, put a large time scale on this since the time selector applies to the data in the buckets - not the date the bucket was rolled over. Also, if you're using default settings, then the standard max bucket size is 750MB so a small bucket size is 75MB. In general, if you're running the original query I gave you, you want to run it for yesterday or the last 24 hours to get semi-accurate results.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| dbinspect index=_* index=*
| search state!=hot
| convert ctime(startEpoch) as startTime
| convert ctime(endEpoch)   as endTime
| search sizeOnDiskMB &amp;lt; 75
| sort sizeOnDiskMB
| eval sizeOnDiskMB=round(sizeOnDiskMB, 2)
| stats values(splunk_server) as splunk_servers
        values(sizeOnDiskMB)  as sizesOnDiskMB
        values(modTime)       as modTimes
    by index id startTime endTime eventCount hostCount sourceTypeCount sourceCount state tsidxState
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Another variation to get bucket size statistics&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| dbinspect index=_* index=*
| search state!=hot
| convert ctime(startEpoch) as startTime
| convert ctime(endEpoch)   as endTime
| stats count
      min(sizeOnDiskMB) as MinSizeOnDiskMB
      avg(sizeOnDiskMB) as AvgSizeOnDiskMB
      max(sizeOnDiskMB) as MaxSizeOnDiskMB
  by index
| sort AvgSizeOnDiskMB
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Once you find a small bucket, get info about it:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| dbinspect index=[index]
| search bucketId="[index]~197~C69837B0-EF8A-47EA-B75E-3640B0F6BB13"
| convert ctime(startEpoch) as startTime 
| convert ctime(endEpoch)   as endTime
| table bucketId id splunk_server index state modTime startTime endTime hostCount sourceTypeCount sourceCount eventCount sizeOnDiskMB path
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Copy the bucketId into this query over the time period of startTime to endTime:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=[index]
| eval cd = _cd, bkt = _bkt
| search bkt="[index]~197~C69837B0-EF8A-47EA-B75E-3640B0F6BB13"
| stats count by host sourcetype source bkt
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If it's not blatantly obvious by this point, try this query. 1 hour worked for latency for me, but you may need to adjust&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=[index]
| eval   latency_hours = round(abs((_indextime-_time)/60/60), 2)
| search latency_hours &amp;gt; 1
| sort - latency_hours
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Or, instead of sort,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| stats count max(latency_hours) avg(latency_hours) by index splunk_server host sourcetype source
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 27 Aug 2019 15:41:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435714#M85791</guid>
      <dc:creator>jacobpevans</dc:creator>
      <dc:date>2019-08-27T15:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of small of buckets is very high and exceeded the red thresholds...-When the red warning will disappear after fixed parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435715#M85792</link>
      <description>&lt;P&gt;Thank you so much. I will test these searches and return back.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 06:43:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435715#M85792</guid>
      <dc:creator>net1993</dc:creator>
      <dc:date>2019-08-28T06:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of small of buckets is very high and exceeded the red thresholds...-When the red warning will disappear after fixed parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435716#M85793</link>
      <description>&lt;P&gt;Great answer, just helped me to find an issue! Thanks&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2020 23:15:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435716#M85793</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2020-02-18T23:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of small of buckets is very high and exceeded the red thresholds...-When the red warning will disappear after fixed parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435717#M85794</link>
      <description>&lt;P&gt;Happy to share something that took much longer than it should've. Thanks for marking as answer MuS, cheers.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 20:54:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435717#M85794</guid>
      <dc:creator>jacobpevans</dc:creator>
      <dc:date>2020-03-05T20:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of small of buckets is very high and exceeded the red thresholds...-When the red warning will disappear after fixed parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435718#M85795</link>
      <description>&lt;P&gt;I encountered this problem as well. &lt;BR /&gt;
The alerts was triggered by restarting an indexer cluster peer, which caused this peer to roll all its indexes. I believe this is just a one-time thing, and the internal logs shows that the hotBucketRoller is working perfectly normal. &lt;BR /&gt;
My problem is that the alerts stayed here for almost a day now. &lt;BR /&gt;
@jacobevans Have you found how long the health status alert will stay?&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 08:54:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435718#M85795</guid>
      <dc:creator>natalielam</dc:creator>
      <dc:date>2020-05-28T08:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of small of buckets is very high and exceeded the red thresholds...-When the red warning will disappear after fixed parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435719#M85796</link>
      <description>&lt;P&gt;I'm not sure. It seemed to be in the range of 24 hours, but I could never perfectly emulate it.&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 22:02:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435719#M85796</guid>
      <dc:creator>jacobpevans</dc:creator>
      <dc:date>2020-05-28T22:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of small of buckets is very high and exceeded the red thresholds...-When the red warning will disappear after fixed parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435720#M85797</link>
      <description>&lt;P&gt;My error disappear once I initiated a restart. It seems that after the restart, Splunk reruns the search and the issue is gone.&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 04:15:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435720#M85797</guid>
      <dc:creator>natalielam</dc:creator>
      <dc:date>2020-05-29T04:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of small of buckets is very high and exceeded the red thresholds...-When the red warning will disappear after fixed parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435721#M85798</link>
      <description>&lt;P&gt;That's good to know. I wonder if running the health check might also fix it without the need for a restart.&lt;/P&gt;</description>
      <pubDate>Sun, 31 May 2020 17:16:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-percentage-of-small-of-buckets-is-very-high-and-exceeded-the/m-p/435721#M85798</guid>
      <dc:creator>jacobpevans</dc:creator>
      <dc:date>2020-05-31T17:16:03Z</dc:date>
    </item>
  </channel>
</rss>

