Deployment Architecture

Modify Splunk health checks - The percentage of small buckets created over the last hour is high

_joe
Contributor

Hello all,

Looking for a way to modify the Splunk Health Check for small buckets. Specifically, I would like the healthcheck to exclude certain indexes.

For example, I like knowing if I am getting too many small buckets... but not if it is for my test index.

 Buckets

  • Root Cause(s):
    • The percentage of small buckets (100%) created over the last hour is high and exceeded the red thresholds (50%) for index=test, and possibly more indexes, on this indexer. At the time this alert fired, total buckets created=6, small buckets=6
    • The percentage of small buckets (100%) created over the last hour is high and exceeded the red thresholds (50%) for index=test, and possibly more indexes, on this indexer. At the time this alert fired, total buckets created=5, small buckets=5
Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I was looking into this today for a similar problem with a different health check.  It turns out we can adjust the threshold for when the check turns yellow or red, but can't change the check itself.  IOW, the search is hardcoded.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...