Deployment Architecture

Roll buckets that are in "Cannot fix search count as the bucket hasn't rolled yet" state

alonsocaio
Contributor

Is there any way to automatically roll buckets that are in the "Cannot fix search count as the bucket hasn't rolled yet" state? Every time that any of my indexers restarts It causes some buckets to stay in fixing mode because they have not rolled yet.

This is causing some impact my Enterprise Security performance, since some of the correlation searches will not run when I have lots of buckets in fixing mode.

0 Karma
1 Solution

codebuilder
Influencer

You can manually roll all hot buckets from hot to warm at the index level:

splunk _internal call /data/indexes/<index_name>/roll-hot-buckets -auth <admin_username>:<admin_password>
----
An upvote would be appreciated and Accept Solution if it helps!

View solution in original post

codebuilder
Influencer

You can manually roll all hot buckets from hot to warm at the index level:

splunk _internal call /data/indexes/<index_name>/roll-hot-buckets -auth <admin_username>:<admin_password>
----
An upvote would be appreciated and Accept Solution if it helps!

alonsocaio
Contributor

Thanks, I guess that this will help me!

0 Karma

muizash
Path Finder

Where to run this command?

0 Karma

codebuilder
Influencer

On the indexers.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...