Splunk Dev

INFO BucketMover - will attempt to freeze: candidate='/splunk/_internaldb/colddb/rb_1522879201_152.....'

halbeisendv
Path Finder

Hello - Searched splunk.answers.com and found this. I have the same problem in a 6.6.4 environment in May 2018. How do I resolve this issue? Thanks.

Hi, I am getting the below error in splunkd.log :

07-24-2014 01:30:51.609 +0200 INFO BucketMover - will attempt to freeze: candidate='/opt/SP/apps/splunk/splunk-6.0.1/var/lib/splunk/rest/db/db_1392823223_1392819715_1' because

frozenTimePeriodInSecs=2419200 exceeds difference between now=1406158251 and latest=1392823223
07-24-2014 01:30:51.664 +0200 ERROR BucketMover - sizeBytes=12288 candidateBytes=19456
07-24-2014 01:30:51.760 +0200 ERROR BucketMover - sizeBytes=1486336 candidateBytes=1574400

Please let me know how to solve this one !!

Tags (1)
0 Karma

jkat54
SplunkTrust
SplunkTrust

This is a known bug in 6.0.1. Please upgrade to resolve the issue. More details can be found on this previous answer:

https://answers.splunk.com/answers/124224/what-is-error-bucketmover-sizebytes-xxx-candidatebytes-yyy...

0 Karma

jkat54
SplunkTrust
SplunkTrust

This event by itself is not a problem. It happens when data freezes.

To adjust when it occurs see the indexes.conf documentation (click on indexes.conf).

you would increase frozenTimePeriodInSecs to keep data longer. As it is currently set to 28 days according to the events... most of your data should be rolling to frozen when its older than 28-30 days. Depending on the data ingestion volume and other indexes.conf settings.

This website has a calculator that will even tell you how to set your indexes.conf: https://splunk-sizing.appspot.com/

0 Karma

gjanders
SplunkTrust
SplunkTrust

Were you referring to the INFO message or to the:
07-24-2014 01:30:51.664 +0200 ERROR BucketMover - sizeBytes=12288 candidateBytes=19456
07-24-2014 01:30:51.760 +0200 ERROR BucketMover - sizeBytes=1486336 candidateBytes=1574400

?

The INFO message is definitely harmless here but I suspect the question is about the ERROR statements

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...