- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
"Got Done key for an unknown bucket without getting any data"

nickhills
Ultra Champion
05-18-2015
04:50 AM
I have a MultiSite indexing cluster, and a single Peer int site 2 is repeatedly reporting:
ERROR TcpInputProc - event=replicationData status=failed err="Got Done key for an unknown bucket without getting any data"
150 or so times at once.
restarting the peer (with cluster maint mode set) has had no effect.
Obviously there is no indication if this is one bucket many times, or lots of buckets.
I'm at a bit of loss how to diagnose further, but wonder if I should stop the indexer and let the cluster fixup, and then bring the indexer back online, unless anyone can provide a more scientific approach.
If my comment helps, please give it a thumbs up!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

bohanlon_splunk

Splunk Employee
08-21-2017
04:05 AM
Reading this might help:
https://docs.splunk.com/Documentation/Splunk/6.5.2/Indexer/Anomalousbuckets
This query might also be useful:
| rest /services/cluster/master/info
| fields buckets_to_fix.*.latest.reason
| transpose
| rename column AS bucket "row 1" AS reason
| rex field=bucket "buckets_to_fix\.(?.*?)\.latest\.reason"
| rex field=bucket "(?[^~]*?)~"
| rex mode=sed field=reason "s/[0-9A-Z]{8}-[0-9A-Z]{4}-[0-9A-Z]{4}-[0-9A-Z]{4}-[0-9A-Z]{12}/{PEER}/"
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

DalJeanis
Legend
08-21-2017
06:57 AM
@bohanlon [Splunk] - marked the query code but it's still missing the tags. Line 4 looks odd, too, please repost.
