Deployment Architecture

Search peer has the following message: Failed to make bucket = searchable

fbustamantes
Explorer

Hello,

I'm checking a Splunk cluster install that has been working just fine for a while. However, a few weeks ago, we had a networking problem which caused a few problems. We were able to restart the cluster once the problem was gone, and for some reason I started getting these errors all over:

    Search peer <peer_name> has the following message: Failed to make bucket = <bucket_name> searchable, retry count = xxxx

I checked the buckets and identified a few that were having some kind of problems when Splunk tries to make them searchable. I stopped the cluster and run the fsck tool to fix it, however it didn't worked, and I tried looking in Splunkbase to see if anyone had an issue like this, but didn't find anything.

Currently Splunk is working fine, however, the errors a showing a lot, and some people at our production and business enviroments who use Splunk are starting to ask questions, so I would like to be able to fix it so they don't show at all.

Thanks in advance for your help.

Felipe.

rchintalapelli
Engager

Did you find any solution for this issue?

0 Karma

lukejadamec
Super Champion

It sounds like you need to rebuild the buckets. Check and rebuild buckets, you should follow the instructions in this post. They work for me (ignore the title).

http://wiki.splunk.com/Community:PostCrashFsckRepair

rnagheereddy
Explorer

I'm going to be a hypocrite and make the kind of post I hate: "Me too!"

Same msg on my Indexers this morning.

Did you get any assistance/ideas for troubleshooting/resolution?

EDIT: we upgraded to 6.0.2 on all Indexers, Cluster Master and Search Heads. Not seeing these msgs any more.

Get Updates on the Splunk Community!

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...

Cloud Platform | Discontinuing support for TLS version 1.0 and 1.1

Overview Transport Layer Security (TLS) is a security communications protocol that lets two computers, ...