I am getting the error below on my indexer. I know which index / source is causing it, but have no idea how to fix it. I've tried to open a ticket with support, but the "Select Cloud Stack" drop down has zero options, but is required.
The percentage of small buckets (100%) created over the last hour is high and exceeded the red thresholds (50%) for index=s1, and possibly more indexes, on this indexer. At the time this alert fired, total buckets created=12, small buckets=12
You can phone Splunk support and let them know. Have your entitlement number handy when you do.