Deployment Architecture

How is Splunks performance affected when the status of the buckets become red in health check?

Sithima
Explorer

How does Splunk performance affect, when the status of "buckets_created_last_60m" and "percent_small_buckets_created_last_24h" became red in health check?

Labels (1)
Tags (1)
0 Karma

chaker
Contributor

If it is an on going error message then it could lead to performance problems when searching that index. 

It means that all your buckets for a certain index are filling to their max size very quickly. You can change the bucketsize from auto (700MB per bucket) to auto high volume(10GB per bucket) to resolve this.

You can use |dbinspect index=<indexName> to inspect the bucket size for the suspect index

maxDataSize = auto_high_volume

https://docs.splunk.com/Documentation/Splunk/9.0.1/Admin/Indexesconf

 

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...