I have a couple panels that are giving me an error:
Failed to read size=10 event(s) from rawdata in bucket
Rawdata nay be corrupt, see search log
on one of my indexers.
How do find out if there is corruption?
TIA!
David L. Crooks
Clustered or non-clustered indexers?
Hi Crooks,
There are few fixes available if the actual data in bucket is not corrupt.
i am not sure of any fixes if bucket raw data is truly corrupt, probably it cannot be fixed.
Here is a good place to read about fixing bad buckets, first try this and see if it works.
http://wiki.splunk.com/Community:PostCrashFsckRepair
If this fix doesnt work try to rebuild the bucket again, do not change the folder structure and still this doesnt work then the data might be corrupt.
Let me know if this helps.