Deployment Architecture

How is Splunks performance affected when the status of the buckets become red in health check?

Sithima
Explorer

How does Splunk performance affect, when the status of "buckets_created_last_60m" and "percent_small_buckets_created_last_24h" became red in health check?

Labels (1)
Tags (1)
0 Karma

chaker
Contributor

If it is an on going error message then it could lead to performance problems when searching that index. 

It means that all your buckets for a certain index are filling to their max size very quickly. You can change the bucketsize from auto (700MB per bucket) to auto high volume(10GB per bucket) to resolve this.

You can use |dbinspect index=<indexName> to inspect the bucket size for the suspect index

maxDataSize = auto_high_volume

https://docs.splunk.com/Documentation/Splunk/9.0.1/Admin/Indexesconf

 

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...