Deployment Architecture

Fixing Buckets in a Cluster

agodoy
Communicator

I have 84 buckets that are in need of fixing.

The fix-up categories are:

data_safety
replication_factor
search_factor

The reason for the fix up seem to be related to some multi-site clustering configuration I was testing out earlier.

missing={ site2:2 } enough star targets=1

I have since changed the cluster configuration to single site. How do I fix those buckets?

Tags (3)
1 Solution

phoffman_splunk
Splunk Employee
Splunk Employee

after pulling the multi-site config out and confirming it's gone, did you restart the cluster? that would be a good place to start.

I would 1st restart the CM, then rolling-restart the peers and see if the issue was just a "stuck" config.

View solution in original post

phoffman_splunk
Splunk Employee
Splunk Employee

after pulling the multi-site config out and confirming it's gone, did you restart the cluster? that would be a good place to start.

I would 1st restart the CM, then rolling-restart the peers and see if the issue was just a "stuck" config.

agodoy
Communicator

Awesome! That took care of the problem. Thanks a lot.

0 Karma

phoffman_splunk
Splunk Employee
Splunk Employee
0 Karma

agodoy
Communicator

What would be the official method of verifying that the cluster is no longer running in multi-site mode? I am going based on the clustering view of the cluster master.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...