<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question regarding small buckets warning in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Question-regarding-small-buckets-warning/m-p/516853#M145289</link>
    <description>Yes, I suppose so. And totally agree with you that there shouldn't be any warnings on logs if it's possible to avoid. Sooner or later those usually changes to errors &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;r. Ismo</description>
    <pubDate>Sat, 29 Aug 2020 12:01:22 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2020-08-29T12:01:22Z</dc:date>
    <item>
      <title>Question regarding small buckets warning</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Question-regarding-small-buckets-warning/m-p/516049#M144940</link>
      <description>&lt;P&gt;So I'm getting the notice regarding small buckets on an index, 100% small buckets on one particular index. Now this index is a summary index that only gets a small volume of new records every day. So it makes sense that the buckets never get large before they're rolled to warm.&lt;/P&gt;&lt;P&gt;Now for various reason we want to keep this data separate from other indexes, mainly this summary data will live forever whereas&amp;nbsp; other indexes are set for a limited retention period.&lt;/P&gt;&lt;P&gt;The index is tiny, current size is 8MB and it's holding summary info for the past 8 months, 7 small buckets so far this year.&lt;/P&gt;&lt;P&gt;I have two questions:&lt;BR /&gt;1) since this is a small index do I have to worry about it only having small buckets?&lt;BR /&gt;2) Assuming having just small buckets in this particular index doesn't cause any major performance problem for the system overall how do I turn off the alert for this one index?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 14:37:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Question-regarding-small-buckets-warning/m-p/516049#M144940</guid>
      <dc:creator>ernest825</dc:creator>
      <dc:date>2020-08-25T14:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding small buckets warning</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Question-regarding-small-buckets-warning/m-p/516052#M144941</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I'm not suppose that this is a issue. You could just ignore those warnings.&lt;/P&gt;&lt;P&gt;If you want you maybe could try to extend the&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;maxHotSpanSecs&lt;/PRE&gt;&lt;P&gt;but as it's default is 90 days then it's quite obvious that reason for rolling those buckets from hot to warm is something else.&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 14:55:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Question-regarding-small-buckets-warning/m-p/516052#M144941</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-25T14:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding small buckets warning</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Question-regarding-small-buckets-warning/m-p/516852#M145288</link>
      <description>&lt;P&gt;Thanks for your reply &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;Ignoring the warning is what we've been doing until now. It's not something I like doing because sooner or later it may result in some other warning being ignored. Looks like in this case we have no choice.&lt;/P&gt;&lt;P&gt;One thing that I didn't mention in my original post was that we've been using the fill_summary_index.py script to fill in gaps in the summary index and I think that might have created extra buckets resulting eventually in more buckets being rolled after 90 days.&amp;nbsp; And of course there's restarts every so often for OS patching, etc. I doubt that the buckets would become anything other than small even if we doubled maxHotSpanSecs.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Aug 2020 11:33:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Question-regarding-small-buckets-warning/m-p/516852#M145288</guid>
      <dc:creator>ernest825</dc:creator>
      <dc:date>2020-08-29T11:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding small buckets warning</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Question-regarding-small-buckets-warning/m-p/516853#M145289</link>
      <description>Yes, I suppose so. And totally agree with you that there shouldn't be any warnings on logs if it's possible to avoid. Sooner or later those usually changes to errors &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;r. Ismo</description>
      <pubDate>Sat, 29 Aug 2020 12:01:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Question-regarding-small-buckets-warning/m-p/516853#M145289</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-29T12:01:22Z</dc:date>
    </item>
  </channel>
</rss>

