Deployment Architecture

Issues with data rebalance from cluster master

athorat
Communicator

When I use the Data rebalance option from the Cluster master, it shows that it is complete within 10-20 mins
Do not see any data moved from the old indexers to the new indexers which are added in the indexer cluster

Also tried to use :
splunk rebalance cluster-data -action start

and has the same result.

in the UI >> Under the Data Rebalance option>> when I click on "All Indexes" >> it shows only _(indexes)

How do I add all the indexes, pretty sure even the command line is replicating only _internal indexes.

0 Karma

jmantor
Path Finder

There are some bugs in that feature. We've found that we have to restart our cluster master when the data re-balance just seems to get stuck : (

0 Karma

halbeisendv
Path Finder

"bugs in that feature?" Has Splunk Technical Support responded to this issue?

We added five indexers; attempted to rebalance one index. The process stopped at 15%. We restarted the Master, attempted to rebalance, but the process stopped at 15% again.

0 Karma

tfechner
Path Finder

same here on 7.1.2: only first 10 indexes are listed

0 Karma

jmantor
Path Finder

I've just run into something simmilar on Splunk 6.5.6.
We recently added 3 new indexers to a cluster that had 15 Indexers, one at a time and re-balanced the data after each one was brought up. The first two worked just fine, but the third just doesn't seem to get any buckets? The other 17 indexers all have 17-19K+ buckets but, the newest it only has about 200, even after the re-balance has run all weekend long.

0 Karma

support0
Path Finder

Hello,

I had the same issue.

6.5.3

Actually, when you first go to Indexer Clustering Section and select Data Rebalance, and select index : it shows only the 10 first indexes.

But if you go to Indexes, and switch from displaying 10per page to more, then all indexes are displayed in Data Rebalance > Indexes

May be it has been fixed since then.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...