Getting Data In

What is: ERROR BucketMover - sizeBytes=xxx candidateBytes=yyy

rune_hellem
Contributor

Got a lot of logged events in the _internal-index for one of our indexers. First we always see an event like this

02-24-2014 13:43:42.850 +0100 INFO  BucketMover - will attempt to freeze: candidate='e:\splunk\indexes\test\db\db_1389020646_1383541534_0' because frozenTimePeriodInSecs=2592000 exceeds difference between now=1393245822 and latest=1389020646

Then immediately we get an error event like this

02-24-2014 13:43:42.850 +0100 ERROR BucketMover - sizeBytes=176128 candidateBytes=253952

24 events the last 15 minutes, and they keep coming.

Searchhead and indexers on Windows 2012, Splunk 6.0.1 (build 189883)

Tags (2)
1 Solution

jdastmalchi_spl
Splunk Employee
Splunk Employee

jdastmalchi_spl
Splunk Employee
Splunk Employee

This looks like a known issue fixed in 6.1.4. SPL-86189
http://docs.splunk.com/Documentation/Splunk/6.1.3/ReleaseNotes/KnownIssues

rune_hellem
Contributor

Did update on 1'st of October to 6.1.4, no errors seen since then.

rune_hellem
Contributor

2,018 events (08/09/2014 00:00:00.000 to 08/09/2014 21:41:16.000)

So...no, still an issue

Now using Splunk 6.1.3 build 220630

0 Karma

jonathan_cooper
Communicator

Still no help on this? I am seeing this same issue, also getting authentication errors/timeouts on search peers periodically. Thought it had to do with too many search jobs, but ruled that out when I disabled everything.

0 Karma

rune_hellem
Contributor

93 events last 60 minutes, so sorry - still an issue here as well.

0 Karma

theouhuios
Motivator

Any update on this? Seeing it on linux too

0 Karma

rune_hellem
Contributor

Now running Splunk 6.1.1 build 207789, still same issue

0 Karma

rune_hellem
Contributor

Checked just now, 1048 events so far today, 5 on one of the indexers, the rest shared on the searchhead and the second indexer, so still an issue

0 Karma

jerinabeham
Explorer

We have also got a ton of this error.
Could anyone please throw some light on this error?

0 Karma
Get Updates on the Splunk Community!

Financial Services Industry Use Cases, ITSI Best Practices, and More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Splunk Federated Analytics for Amazon Security Lake

Thursday, November 21, 2024  |  11AM PT / 2PM ET Register Now Join our session to see the technical ...

Splunk With AppDynamics - Meet the New IT (And Engineering) Couple

Wednesday, November 20, 2024  |  10AM PT / 1PM ET Register Now Join us in this session to learn all about ...