Deployment Architecture

Is it "safe" to copy buckets across indexers when buckets get corrupt?

ddrillic
Ultra Champion

On our index cluster, certain buckets got corrupt on one indexer. Is it possible to copy a bucket from a healthy indexer over the corrupt one?

Tags (1)
0 Karma

Masa
Splunk Employee
Splunk Employee

(Answer to this old question)
Yes, possible as a workaround. In general, if you delete the corrupted bucket (splunk must be stopped, and remove the bucket and restart it again), Cluster Master should detect Replication factor is not met, and create a copy to a cluster peer.

In v6.5, there is action in fix-up bucket status page and select "remove/resync, etc"

If it is pre-v6.5, "remove_from_peer" REST call may be useful without stopping Splunk.
( ref: http://docs.splunk.com/Documentation/Splunk/6.5.2/RESTREF/RESTclusterExamples )

If that is failing, potentially somehow source bucket itself is corrupted. I would suggest to run;

splunk fsck repair --one-bucket --bucket-path=<bucket_path>

Hope this helps for people visiting this answer.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...