Hello,
I'm checking a Splunk cluster install that has been working just fine for a while. However, a few weeks ago, we had a networking problem which caused a few problems. We were able to restart the cluster once the problem was gone, and for some reason I started getting these errors all over:
Search peer <peer_name> has the following message: Failed to make bucket = <bucket_name> searchable, retry count = xxxx
I checked the buckets and identified a few that were having some kind of problems when Splunk tries to make them searchable. I stopped the cluster and run the fsck tool to fix it, however it didn't worked, and I tried looking in Splunkbase to see if anyone had an issue like this, but didn't find anything.
Currently Splunk is working fine, however, the errors a showing a lot, and some people at our production and business enviroments who use Splunk are starting to ask questions, so I would like to be able to fix it so they don't show at all.
Thanks in advance for your help.
Felipe.
Did you find any solution for this issue?
It sounds like you need to rebuild the buckets. Check and rebuild buckets, you should follow the instructions in this post. They work for me (ignore the title).
I'm going to be a hypocrite and make the kind of post I hate: "Me too!"
Same msg on my Indexers this morning.
Did you get any assistance/ideas for troubleshooting/resolution?
EDIT: we upgraded to 6.0.2 on all Indexers, Cluster Master and Search Heads. Not seeing these msgs any more.