Deployment Architecture

Fixup Tasks (Pending) are stuck with bucket status: "cannot fix up search factor as bucket is not serviceable;"

keio_splunk
Splunk Employee
Splunk Employee

Fixup tasks (Pending) for our indexer cluster could not be fixed and the bucket current status is reporting: "cannot fix up search factor as bucket is not serviceable;".

WARN message in splunkd.log:
WARN CMMaster - event=handleSyncError bid=network~xxx~xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx src=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx tgt=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx

alt text

0 Karma
1 Solution

keio_splunk
Splunk Employee
Splunk Employee

The pending bucket status are cleared after opening the management port (8089) between the indexers. It is a requirement for the management port to be opened between the indexers. Refer to "Ports that the cluster nodes use" in Splunk Documentation:

https://docs.splunk.com/Documentation/Splunk/7.2.3/Indexer/Systemrequirements#Ports_that_the_cluster...

View solution in original post

0 Karma

keio_splunk
Splunk Employee
Splunk Employee

The pending bucket status are cleared after opening the management port (8089) between the indexers. It is a requirement for the management port to be opened between the indexers. Refer to "Ports that the cluster nodes use" in Splunk Documentation:

https://docs.splunk.com/Documentation/Splunk/7.2.3/Indexer/Systemrequirements#Ports_that_the_cluster...

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...