Deployment Architecture

Issues with data rebalance from cluster master

athorat
Communicator

When I use the Data rebalance option from the Cluster master, it shows that it is complete within 10-20 mins
Do not see any data moved from the old indexers to the new indexers which are added in the indexer cluster

Also tried to use :
splunk rebalance cluster-data -action start

and has the same result.

in the UI >> Under the Data Rebalance option>> when I click on "All Indexes" >> it shows only _(indexes)

How do I add all the indexes, pretty sure even the command line is replicating only _internal indexes.

0 Karma

jmantor
Path Finder

There are some bugs in that feature. We've found that we have to restart our cluster master when the data re-balance just seems to get stuck : (

0 Karma

halbeisendv
Path Finder

"bugs in that feature?" Has Splunk Technical Support responded to this issue?

We added five indexers; attempted to rebalance one index. The process stopped at 15%. We restarted the Master, attempted to rebalance, but the process stopped at 15% again.

0 Karma

tfechner
Path Finder

same here on 7.1.2: only first 10 indexes are listed

0 Karma

jmantor
Path Finder

I've just run into something simmilar on Splunk 6.5.6.
We recently added 3 new indexers to a cluster that had 15 Indexers, one at a time and re-balanced the data after each one was brought up. The first two worked just fine, but the third just doesn't seem to get any buckets? The other 17 indexers all have 17-19K+ buckets but, the newest it only has about 200, even after the re-balance has run all weekend long.

0 Karma

support0
Path Finder

Hello,

I had the same issue.

6.5.3

Actually, when you first go to Indexer Clustering Section and select Data Rebalance, and select index : it shows only the 10 first indexes.

But if you go to Indexes, and switch from displaying 10per page to more, then all indexes are displayed in Data Rebalance > Indexes

May be it has been fixed since then.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...