Deployment Architecture
Highlighted

Indexer Clustering Search Factor and Replication Factor not Met for Streaming Buckets

Communicator

It is common to see that one or two buckets may not be meeting the Search Factor, although the data from the respective buckets will be searchable.

Many times these buckets are hot buckets, which mean these buckets will not meet the Search Factor unless the bucket is rolled from hot to warm. When you view these buckets using the Bucket REST endpoint using the URL below, the bucket will show status of 'StreamingSource' or 'StreamingTarget'

Bucket REST endpoint:
https://<CLUSTERMASTERURI>:<CLUSTERMASTERPORT>/services/cluster/master/buckets/<BUCKET_ID>

How to address such a situation?

0 Karma
Highlighted

Re: Indexer Clustering Search Factor and Replication Factor not Met for Streaming Buckets

Motivator

Run the following curl command on the index where the bucket needs to be fixed.

HOST is the StreamingSource server name, PORT being 8089, YOUR_INDEX is the index needing to roll

 curl -k -u admin:changeme https://HOST:PORT/services/data/indexes/YOUR_INDEX/roll-hot-buckets -X POST

example of _audit something like

 curl -k -u admin:PASSWORD https://idx2:8089/services/data/indexes/_audit/roll-hot-buckets -X POST

View solution in original post

Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.