Deployment Architecture

Modify Splunk health checks - The percentage of small buckets created over the last hour is high

_joe
Contributor

Hello all,

Looking for a way to modify the Splunk Health Check for small buckets. Specifically, I would like the healthcheck to exclude certain indexes.

For example, I like knowing if I am getting too many small buckets... but not if it is for my test index.

 Buckets

  • Root Cause(s):
    • The percentage of small buckets (100%) created over the last hour is high and exceeded the red thresholds (50%) for index=test, and possibly more indexes, on this indexer. At the time this alert fired, total buckets created=6, small buckets=6
    • The percentage of small buckets (100%) created over the last hour is high and exceeded the red thresholds (50%) for index=test, and possibly more indexes, on this indexer. At the time this alert fired, total buckets created=5, small buckets=5
Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I was looking into this today for a similar problem with a different health check.  It turns out we can adjust the threshold for when the check turns yellow or red, but can't change the check itself.  IOW, the search is hardcoded.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...