Deployment Architecture

How to fix bucket replication issues?

brent_weaver
Builder

I am unable to search my indexed data from now in splunk. We have a rather large env, 53 indexers. I am seeing that there are prending_build. How to I rememdy this situation?

FBD33A23-C500-47E3-9E82-0AB11F56AB35
        active_bundle_id:D260DA9609DA32CC4A51CA307BEA131E
        base_generation_id:130560
        bucket_count:1910
        delayed_buckets_to_discard:
        fixup_set:
        heartbeat_started:1
        host_port_pair:10.9.1.9:8089
        indexing_disk_space:13191985758208
        is_searchable:1
        is_valid_bundle:1
        label:ip-10-9-1-9
        last_heartbeat:1517090749
        last_validated_bundle:D260DA9609DA32CC4A51CA307BEA131E
        latest_bundle_id:D260DA9609DA32CC4A51CA307BEA131E
        pending_builds:
            us_west_prod_predix_firehose~779~51A2E4CB-11EA-4585-84C7-D31FA864754C
        pending_job_count:0
        primary_count:1266
        primary_count_remote:1286
        register_search_address:10.9.1.9:8089
        replication_count:0
        replication_port:9887
        replication_use_ssl:0
        site:site2
        status:Up
        summary_replication_count:0
Tags (1)
0 Karma

HiroshiSatoh
Champion

If it is a temporary replication problem time will be resolved.

What is the load situation of each indexer? Is the load biased on one?

In a clustered environment I know, there was a case in which loading concentrated on one indexer due to one huge log, making searching impossible.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...