HI, Please tell me how to solve the message below.
ERROR MSG = Search on most recent data has completed. Expect slower search speeds as we search the reduced buckets.
What do you mean by "solve"? This is not an error.
You have tsidx reduction enabled in your environment so the indexes occupy less space but the older buckets (which get reduced after configured time) are much less efficient to search.
https://docs.splunk.com/Documentation/Splunk/9.0.2/Indexer/Reducetsidxdiskusage
What do you mean by "solve"? This is not an error.
You have tsidx reduction enabled in your environment so the indexes occupy less space but the older buckets (which get reduced after configured time) are much less efficient to search.
https://docs.splunk.com/Documentation/Splunk/9.0.2/Indexer/Reducetsidxdiskusage