Deployment Architecture

Number of buckets report "unexpected mask=11 expected=0"

tomasztomasz
Loves-to-Learn

After failing over from the active cluster master to the redundant node (which holds the same configuration), 15 buckets report now 

 

slave bucket=XXXXXX has unexpected mask=11 expected=0

 

This results in search factor not met for the corresponding indices. 

I can see the cluster master running the "CMChangeMasksJob" in regular intervals but it looks to me it just can't handle those 15 buckets. 

I am looking for any hints how to tackle this. First and foremost, what is a bucket mask? Are my buckets corrupted? Can I try to update the mask manually?

 

Labels (1)
0 Karma

tomasztomasz
Loves-to-Learn

Simply resolved by restarting the Splunk instance running on the cluster master 🤣

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...