<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Removed index from indexes.conf but still getting errors about index in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Removed-index-from-indexes-conf-but-still-getting-errors-about/m-p/318225#M163556</link>
    <description>&lt;P&gt;I tried removing an index from /opt/splunk/etc/master-apps/_cluster/local/indexes.conf as per &lt;A href="https://answers.splunk.com/answers/471105/deleting-an-index-in-a-distributed-splunk-deployme.html"&gt;https://answers.splunk.com/answers/471105/deleting-an-index-in-a-distributed-splunk-deployme.html&lt;/A&gt; and &lt;A href="https://answers.splunk.com/answers/387161/official-way-to-clean-indexed-data-from-index-clus.html"&gt;https://answers.splunk.com/answers/387161/official-way-to-clean-indexed-data-from-index-clus.html&lt;/A&gt;, restarted the cluster, but the index is still present in the cluster. There are errors in the web GUI that read "cannot replicate as bucket is not serviceable", and splunkd is continuously scrolling:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;01-17-2018 09:54:33.389 -0800 INFO  CMReplicationRegistry - Finished replication: bid=akamailogs~220~A3DE1411-41D8-44A2-811A-B30A7284FAB2 src=A12B1B95-3FA8-459A-BD3A-357F88B6B4EC target=A3DE1411-41D8-44A2-811A-B30A7284FAB2
01-17-2018 09:54:33.389 -0800 INFO  CMMaster - event=handleReplicationError bid=akamailogs~220~A3DE1411-41D8-44A2-811A-B30A7284FAB2 tgt=A3DE1411-41D8-44A2-811A-B30A7284FAB2 peer_name=splunk03.s2prod msg='target doesn't have bucket now. ignoring'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any ideas how to get splunk to completey forget about this index?&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jan 2018 17:58:01 GMT</pubDate>
    <dc:creator>wsanderstii</dc:creator>
    <dc:date>2018-01-17T17:58:01Z</dc:date>
    <item>
      <title>Removed index from indexes.conf but still getting errors about index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Removed-index-from-indexes-conf-but-still-getting-errors-about/m-p/318225#M163556</link>
      <description>&lt;P&gt;I tried removing an index from /opt/splunk/etc/master-apps/_cluster/local/indexes.conf as per &lt;A href="https://answers.splunk.com/answers/471105/deleting-an-index-in-a-distributed-splunk-deployme.html"&gt;https://answers.splunk.com/answers/471105/deleting-an-index-in-a-distributed-splunk-deployme.html&lt;/A&gt; and &lt;A href="https://answers.splunk.com/answers/387161/official-way-to-clean-indexed-data-from-index-clus.html"&gt;https://answers.splunk.com/answers/387161/official-way-to-clean-indexed-data-from-index-clus.html&lt;/A&gt;, restarted the cluster, but the index is still present in the cluster. There are errors in the web GUI that read "cannot replicate as bucket is not serviceable", and splunkd is continuously scrolling:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;01-17-2018 09:54:33.389 -0800 INFO  CMReplicationRegistry - Finished replication: bid=akamailogs~220~A3DE1411-41D8-44A2-811A-B30A7284FAB2 src=A12B1B95-3FA8-459A-BD3A-357F88B6B4EC target=A3DE1411-41D8-44A2-811A-B30A7284FAB2
01-17-2018 09:54:33.389 -0800 INFO  CMMaster - event=handleReplicationError bid=akamailogs~220~A3DE1411-41D8-44A2-811A-B30A7284FAB2 tgt=A3DE1411-41D8-44A2-811A-B30A7284FAB2 peer_name=splunk03.s2prod msg='target doesn't have bucket now. ignoring'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any ideas how to get splunk to completey forget about this index?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 17:58:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Removed-index-from-indexes-conf-but-still-getting-errors-about/m-p/318225#M163556</guid>
      <dc:creator>wsanderstii</dc:creator>
      <dc:date>2018-01-17T17:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: Removed index from indexes.conf but still getting errors about index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Removed-index-from-indexes-conf-but-still-getting-errors-about/m-p/318226#M163557</link>
      <description>&lt;P&gt;was your cluster consistent before you removed the index?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 18:04:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Removed-index-from-indexes-conf-but-still-getting-errors-about/m-p/318226#M163557</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-17T18:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: Removed index from indexes.conf but still getting errors about index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Removed-index-from-indexes-conf-but-still-getting-errors-about/m-p/318227#M163558</link>
      <description>&lt;P&gt;Pre-empting your reply - this should only be likely to occur if your cluster was inconsistent when you removed the index, if your cluster was full sf/rf then you may have other underlying issues.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;If this is a production cluster, you may wish to consult with Splunk support&lt;/STRONG&gt; - but if your cluster is expendable (and with all the normal caveats about taking advice from some random guy on the internet)&lt;/P&gt;

&lt;P&gt;Run this query to get a list of buckets which have failed to replicate properly:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal event=handleReplicationError bid=akamilogs*|dedup bid|table bid
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Export that as a csv (confirming all the buckets are ones you want to remove)&lt;/P&gt;

&lt;P&gt;Depending on the total number of buckets you can either remove them one by one using:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;curl -k -u admin:changeme -X POST "https://clusterMAaterAddress:8089/services/cluster/master/buckets/akamilogs~xxxx~xxxxxxxxx-xxxx-xxxxx-xxxxx-xxxxxxxxx/remove_all"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Or this script will delete the lot (run the script in the same folder as the csv)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#!/bin/bash

cat bad_buckets.csv | while read bucket
do
    curl -k -u admin:changeme -X POST "https://clusterMAaterAddress:8089/services/cluster/master/buckets/$bucket/remove_all"
done
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You would be wise to test this by removing one or two buckets, and confirming that the errors stop for those bids. Also, I have typed this on a train with no access to splunk, so it has not been tested, so please take every precaution - peer review / backups / mother on speed dial...&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 18:34:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Removed-index-from-indexes-conf-but-still-getting-errors-about/m-p/318227#M163558</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-17T18:34:30Z</dc:date>
    </item>
  </channel>
</rss>

