Deployment Architecture

Indexer Clustering Search Factor and Replication Factor not Met for Streaming Buckets

sat94541
Communicator

It is common to see that one or two buckets may not be meeting the Search Factor, although the data from the respective buckets will be searchable.

Many times these buckets are hot buckets, which mean these buckets will not meet the Search Factor unless the bucket is rolled from hot to warm. When you view these buckets using the Bucket REST endpoint using the URL below, the bucket will show status of 'StreamingSource' or 'StreamingTarget'

Bucket REST endpoint:
https://<CLUSTER_MASTER_URI>:<CLUSTER_MASTER_PORT>/services/cluster/master/buckets/<BUCKET_ID>

How to address such a situation?

0 Karma
1 Solution

rbal_splunk
Splunk Employee
Splunk Employee

Run the following curl command on the index where the bucket needs to be fixed.

HOST is the StreamingSource server name, PORT being 8089, YOUR_INDEX is the index needing to roll

 curl -k -u admin:changeme https://HOST:PORT/services/data/indexes/YOUR_INDEX/roll-hot-buckets -X POST

example of _audit something like

 curl -k -u admin:PASSWORD https://idx2:8089/services/data/indexes/_audit/roll-hot-buckets -X POST

View solution in original post

rbal_splunk
Splunk Employee
Splunk Employee

Run the following curl command on the index where the bucket needs to be fixed.

HOST is the StreamingSource server name, PORT being 8089, YOUR_INDEX is the index needing to roll

 curl -k -u admin:changeme https://HOST:PORT/services/data/indexes/YOUR_INDEX/roll-hot-buckets -X POST

example of _audit something like

 curl -k -u admin:PASSWORD https://idx2:8089/services/data/indexes/_audit/roll-hot-buckets -X POST
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...