Deployment Architecture

How do I manually identify excess buckets in a multisite cluster?

ashnet16_2
New Member

Hello,

When trying to remove all excess buckets via the Cluster Master in a multisite indexer clustered environment, we don't see all excess buckets being removed, only some. Is it possible that the cluster master is only removing excess buckets from one site and not the other? Also, is there a way to identify excess buckets? Do excess buckets have a particular prefix? If so, is it save to remove them manually?

0 Karma
1 Solution

s2_splunk
Splunk Employee
Splunk Employee

Excess buckets are the result of corrective action taken by the cluster master upon peer node failure to ensure that your configured replication factor is being met in the cluster. Because the cluster master at some point decided that certain buckets need to be replicated to meet your RF/SF, these buckets don't have any naming conventions that 'mark' them as excess buckets, they look like any other bucket. It is the fact that you have more copies of a given bucket than needed to satisfy RF/SF makes them 'excessive'. I strongly advise you to not try and take any manual action without involvement of Splunk support.
If you believe that the UI driven action does not remove all excess buckets AND your cluster is otherwise healthy, i.e. RF/SF are met and all peer nodes are up, please file a case with Splunk support.

View solution in original post

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Excess buckets are the result of corrective action taken by the cluster master upon peer node failure to ensure that your configured replication factor is being met in the cluster. Because the cluster master at some point decided that certain buckets need to be replicated to meet your RF/SF, these buckets don't have any naming conventions that 'mark' them as excess buckets, they look like any other bucket. It is the fact that you have more copies of a given bucket than needed to satisfy RF/SF makes them 'excessive'. I strongly advise you to not try and take any manual action without involvement of Splunk support.
If you believe that the UI driven action does not remove all excess buckets AND your cluster is otherwise healthy, i.e. RF/SF are met and all peer nodes are up, please file a case with Splunk support.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...