<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bucket Flap in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Bucket-Flap/m-p/486988#M8057</link>
    <description>&lt;P&gt;Thank you: I will apply your fix but your explanation has already been pretty straightforwarded.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2020 10:01:09 GMT</pubDate>
    <dc:creator>adol83</dc:creator>
    <dc:date>2020-04-28T10:01:09Z</dc:date>
    <item>
      <title>Bucket Flap</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Bucket-Flap/m-p/486986#M8055</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I'm new here and I wanted some help for this issue.&lt;BR /&gt;
My incident is getting many errors for a bucket replication that keeps flapping up/down. In the master dashboard I have the errors "search factor is not met" and "replication factor is not met" along with main page warnings like "msg='target doesn't have bucket now. ignoring' " and "making bucket serviceable, we have enough peers now " that suggests me it's flapping other than the up/down I see in the master dashboard.&lt;/P&gt;

&lt;P&gt;I have a little infrastructure with&lt;/P&gt;

&lt;P&gt;1 Master&lt;BR /&gt;
2 Indexers&lt;BR /&gt;
1 Search Head &lt;BR /&gt;
1 Heavy Forwarder&lt;/P&gt;

&lt;P&gt;My configuration on local (that should override the default server.conf) is fine having replication_factor=2 and search_factor=2 but it seems that no matter which change I apply the always stays up.&lt;BR /&gt;
I tried to resync the bucket but actually I'm not even sure it did it. However, among my fix up tasks I have 2, 1 for replication factor and 1 for search factor &lt;/P&gt;

&lt;P&gt;For what concern search factor I have the following:&lt;/P&gt;

&lt;P&gt;fixup reason: unmet rf&lt;BR /&gt;
current status: Missing enough suitable candidates to create searchable copy in order to meet replication policy. Missing={ default:1 } &lt;/P&gt;

&lt;P&gt;for what concern replication factor:&lt;/P&gt;

&lt;P&gt;fixup reason: unmet rf&lt;BR /&gt;
current status: empty&lt;/P&gt;

&lt;P&gt;could you please let me know?&lt;/P&gt;

&lt;P&gt;I have some basic knowledge of administration and clustering by reading Splunk docs but I'm not sure I am really into yet.&lt;BR /&gt;
splunk btool server list --debug &lt;BR /&gt;
give me an output whereas replication_factor in local config is 2 and in default config is 3 but as far as I know local config in this case should override the default one.&lt;/P&gt;

&lt;P&gt;I'm stuck!&lt;/P&gt;

&lt;P&gt;Thank you in advance&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:13:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Bucket-Flap/m-p/486986#M8055</guid>
      <dc:creator>adol83</dc:creator>
      <dc:date>2020-09-30T05:13:16Z</dc:date>
    </item>
    <item>
      <title>Re: Bucket Flap</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Bucket-Flap/m-p/486987#M8056</link>
      <description>&lt;P&gt;Your issue is with the search_factor setting. It cannot be set to a value of 2 with a single search head. Search artifacts are stored on the search heads. Since you have only one search head, but a setting of 2, it is trying to replicate artifacts but nowhere to put them.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 20:40:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Bucket-Flap/m-p/486987#M8056</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2020-04-27T20:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: Bucket Flap</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Bucket-Flap/m-p/486988#M8057</link>
      <description>&lt;P&gt;Thank you: I will apply your fix but your explanation has already been pretty straightforwarded.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 10:01:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Bucket-Flap/m-p/486988#M8057</guid>
      <dc:creator>adol83</dc:creator>
      <dc:date>2020-04-28T10:01:09Z</dc:date>
    </item>
  </channel>
</rss>

