We have two indexers in our cluster and RF and SF are met. But the total number of buckets in one of the indexer is reducing day by day. present situation is, one indexer contain 25000 Buckets and other contain 5000 Buckets. Did anyone faced this type of situation? Please help me whether is this normal or need to worry?
looks wierd to me. I also administer a indexer cluster and I'm used to seeing diffences in bucket count aswell, but nothing that looks this extreme.
How much data are you indexing on average per day?
As TStrauch said, whats your RF?
What you could do for troubleshooting is following this documentation to list excess buckets.
Don't remove them yet, just maybe show us the results of the splunk list excess-buckets command.