Getting Data In

Unexpected failure to parse bucket (5.0.3 indexer)

the_wolverine
Champion

I'm seeing a lot of these WARNs reported by indexer and would like to know what it means:

03-12-2014 17:57:38.135 +0000 WARN
BucketMover - Unexpected failure to
parse
bucket='/opt/splunk/var/lib/splunk/main/db/hot_v1_3656'

0 Karma

jrodman
Splunk Employee
Splunk Employee

This warning is correct but pointless for a hot bucket. If Splunk incorrectly attempts to parse hot buckets for the time endpoints in some cases, then numbers which indicate the oldest and newest times of the bucket are not available to be parsed. In other words, for hot buckets, attempting to parse the names will produce this warning.

My best information (grain of salt here) suggests that we are not currently aware of the reasons why Splunk would parse hot buckets, and we have not been able to produce the problem via any means in Splunk 6.1.

It might be advisable to manually investigate these buckets and see if there's anything unusual about them (missing, truncated files, etc.) that would lead to a problem needing further investigation by Splunk. However it could be that this is just a messaging problem was fixed by changes not specifically targetted at this message between early 5.0.x and 6.1.

More information is welcome.

the_wolverine
Champion

Super appreciate your response, Jrodman.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...