Deployment Architecture

Different number of buckets on cluster

Path Finder

Hello all,

I have a "problem" with a new indexer added in my cluster.
My cluster has two indexers.
The goal is to replace these two indexers by two other with more resources.

So here what I did:

1) realize all the configurations in indexes.conf, server.conf etc
2) add the new indexer in my cluster
3) shut down and remove from the cluster the old indexer
4) wait for the replication finishing.

The problem is that, once replication finished, I have an important number of buckets that missing.
My new server in the cluster has 9500 buckets and the old one, 11500.

When I launch a research for the same time period on the same index but on the new and the second old server, I don't have the same number of results.

I tried the "data rebalance" but nothing...everything is green in the Master node under Indexer clustering.

Is there anyway to force the missing bucket replication?

edit: I've just realized that the problem was already there before the addition of the new server. The removed server has lowest bucket number and lower events in the indexes.

Thank you in advance.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Education - Fast Start Program!

Welcome to Splunk Education! Splunk training programs are designed to enable you to get started quickly and ...

Five Subtly Different Ways of Adding Manual Instrumentation in Java

You can find the code of this example on GitHub here. Please feel free to star the repository to keep in ...

New Splunk APM Enhancements Help Troubleshoot Your MySQL and NoSQL Databases Faster

Splunk Observability has two new enhancements to make it quicker and easier to troubleshoot slow or frequently ...