Getting Data In

Failed to make bucket searchable, Bad Splunk Support advice?

jfaldmomacu
Path Finder

I've been getting this error for a few weeks.

Search peer <indexer> has the following message: Failed to make bucket = main~5360~4D6B6D21-6F08-44EA-B793-EFEB8C344E21 searchable, retry count = 743.

I have a case open with Splunk Support and I wanted to know if their logic or feedback is sound. After stopping the indexer I ran fsck and saw multiple buckets have needed to be rebuilt. They all rebuilt successfully except the one was in the error message. 

After sharing this information and the logs with Support I was told that "For a single bucket you can ignore this warning. Data will still be searchable for this bucket. "

So, should I think all is well because Support told me so and ignore the Health of Splunk Deployment report that shows the "red exclamation mark" icons for Buckets and Data Durability?

jfaldmomacu_0-1641919724910.png

 

 

Labels (1)
0 Karma

Stefanie
Builder

I may not be able to assist but I just wanted to mention that Splunk support has also told me to "ignore" some of those health check items. We ended up having to have a tech from Splunk come onsite to address some of these issues. 

My suggestion would be to spin up a new indexer to replace the indexer with that corrupted bucket. 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...