<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to solve TailReader and buckets errors in Installation</title>
    <link>https://community.splunk.com/t5/Installation/How-to-solve-TailReader-and-buckets-errors/m-p/506944#M6400</link>
    <description>&lt;P&gt;I have just adjusted the parameter maxQueueSize in the outputs.conf file to a grater value in the HeavyForwarder, default is 500Kb. That have solved the issue.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Jul 2020 21:23:27 GMT</pubDate>
    <dc:creator>jorgeisaacm</dc:creator>
    <dc:date>2020-07-01T21:23:27Z</dc:date>
    <item>
      <title>How to solve TailReader and buckets errors</title>
      <link>https://community.splunk.com/t5/Installation/How-to-solve-TailReader-and-buckets-errors/m-p/415255#M5591</link>
      <description>&lt;P&gt;Hi, we have upgraded to 7.2.6 and we are getting errors all the time now. Today we have used 3 GB of our licenses- so not much, however, I have issues below (Images).&lt;/P&gt;
&lt;P&gt;I have 3 questions:&lt;BR /&gt;1) We have a single install (1 search head and 1 indexer) and thinking of moving to 5 indexers and 1 search head, will this help this issue?&lt;BR /&gt;2) What happens when the tail reader is full, who suffers what are the impacts, how can I help this?&lt;BR /&gt;3) What happens when buckets are full, who suffers what are the impacts, how can I help this?&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;BR /&gt;Rob&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7179iD6B020440B8DDCFA/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7180i17B3773FA3AD8FBD/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jun 2020 00:09:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-solve-TailReader-and-buckets-errors/m-p/415255#M5591</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2020-06-06T00:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to solve TailReader and buckets errors</title>
      <link>https://community.splunk.com/t5/Installation/How-to-solve-TailReader-and-buckets-errors/m-p/415256#M5592</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;the first questions that come to my mind are the following:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;From which version did you upgrade to 7.2.6?&lt;/LI&gt;
&lt;LI&gt;Which splunk instances are reporting these errors? Only Universal Forwarders? All of them and if not, which versions are affected?&lt;/LI&gt;
&lt;/UL&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;1) We have a single install(1 search&lt;BR /&gt;
head and 1 indexer) and thinking of&lt;BR /&gt;
moving to 5 indexers and 1 search&lt;BR /&gt;
head, will this help this issue?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;How many GB per day are you ingesting? Why do you want to move to 5 indexers right away? Do you have any experience in building indexer clusters?&lt;BR /&gt;
Moving to 5 indexers would not be advisable without further information. One indexer, under optimal conditions, should be able to index 100+ GB per day depending on some factors like the amount of scheduled searches and ad-hoc searches being ran by users.&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;2) What happens when the tail reader&lt;BR /&gt;
is full, who suffers what are the&lt;BR /&gt;
impacts, how can i help this?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;You are experiencing issues that might be due to timestamping problems. Make sure your data getting indexed has the correct settings applied and _time gets extracted correctly. &lt;A href="https://answers.splunk.com/answers/5590/could-not-send-data-to-the-output-queue.html"&gt;This thread&lt;/A&gt; on answers is also a good starting point for troubleshooting.&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;3) What happens when buckets are full,&lt;BR /&gt;
who suffers what are the impacts, how&lt;BR /&gt;
can i help this?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;A high number of buckets created should be avoided. Because of how Splunk works, it will impact your performance when many buckets have to be opened and kept open (due to the mentioned timestamping problems for example).&lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 09:59:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-solve-TailReader-and-buckets-errors/m-p/415256#M5592</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2019-06-07T09:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to solve TailReader and buckets errors</title>
      <link>https://community.splunk.com/t5/Installation/How-to-solve-TailReader-and-buckets-errors/m-p/415257#M5593</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;Thanks for the answer.&lt;/P&gt;

&lt;P&gt;To answer some questions.&lt;BR /&gt;
From which version did you upgrade to 7.2.6? - &lt;BR /&gt;
[RL]we came from 7.1.6.&lt;/P&gt;

&lt;P&gt;How many GB per day are you ingesting? Why do you want to move to 5 indexers right away? Do you have any experience in building indexer clusters?&lt;/P&gt;

&lt;P&gt;[RL]We are ingesting 40Gb per day on a busy day, but today when i have the issue we have done 3GB. &lt;BR /&gt;
We are thinking of increasing our indexers anyway due to other issues and i wanted to know it it would help here? I dont mind how many i go to but i just want to know if that will help this issue, I have some experience in setting it up.&lt;/P&gt;

&lt;P&gt;Some of our data does not have a time stamps, i am not sure if i can do anything about that as i needed it. I know the specific source type its GC data with no timestamp.&lt;/P&gt;

&lt;P&gt;Thanks in advance for any advice&lt;BR /&gt;
Rob&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 12:31:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-solve-TailReader-and-buckets-errors/m-p/415257#M5593</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2019-06-07T12:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to solve TailReader and buckets errors</title>
      <link>https://community.splunk.com/t5/Installation/How-to-solve-TailReader-and-buckets-errors/m-p/415258#M5594</link>
      <description>&lt;P&gt;Hi @robertlynch2020 , did you find any solution to this issue?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2020 03:49:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-solve-TailReader-and-buckets-errors/m-p/415258#M5594</guid>
      <dc:creator>splunk_abhishek</dc:creator>
      <dc:date>2020-02-24T03:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to solve TailReader and buckets errors</title>
      <link>https://community.splunk.com/t5/Installation/How-to-solve-TailReader-and-buckets-errors/m-p/506944#M6400</link>
      <description>&lt;P&gt;I have just adjusted the parameter maxQueueSize in the outputs.conf file to a grater value in the HeavyForwarder, default is 500Kb. That have solved the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 21:23:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-solve-TailReader-and-buckets-errors/m-p/506944#M6400</guid>
      <dc:creator>jorgeisaacm</dc:creator>
      <dc:date>2020-07-01T21:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to solve TailReader and buckets errors</title>
      <link>https://community.splunk.com/t5/Installation/How-to-solve-TailReader-and-buckets-errors/m-p/593434#M11430</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have the Same issue, since i started monitoring my log files on an other splunk server.&lt;/P&gt;&lt;P&gt;Did you manage to solve your problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Fatma.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 11:07:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-solve-TailReader-and-buckets-errors/m-p/593434#M11430</guid>
      <dc:creator>fatmaBouaziz</dc:creator>
      <dc:date>2022-04-12T11:07:37Z</dc:date>
    </item>
  </channel>
</rss>

