Deployment Architecture

How is Splunks performance affected when the status of the buckets become red in health check?

Sithima
Explorer

How does Splunk performance affect, when the status of "buckets_created_last_60m" and "percent_small_buckets_created_last_24h" became red in health check?

Labels (1)
Tags (1)
0 Karma

chaker
Contributor

If it is an on going error message then it could lead to performance problems when searching that index. 

It means that all your buckets for a certain index are filling to their max size very quickly. You can change the bucketsize from auto (700MB per bucket) to auto high volume(10GB per bucket) to resolve this.

You can use |dbinspect index=<indexName> to inspect the bucket size for the suspect index

maxDataSize = auto_high_volume

https://docs.splunk.com/Documentation/Splunk/9.0.1/Admin/Indexesconf

 

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...