Getting Data In

Why do my indexers in my indexer clustering environment have a different number of buckets?

daniel_augustyn
Contributor

I just deployed Splunk in an indexer cluster deployment, and I've noticed that my indexers have a different number of buckets. Shouldn't they have the same number of buckets since the data is replicated? Or not all buckets get replicated between indexers?

0 Karma
1 Solution

Yasaswy
Contributor

Hi,
Buckets are not just limited to replication activity, they also include data being received. Depending on your deployment and how your forwarders are configured it's possible that some of your systems are forwarding to only few of the indexers in your cluster causing them to have higher bucket counts. Eg: if you have a cluster of 8 indexers with a replication factor of 2, but some of the forwarders in your environment are only set to forward to 3 of these, you will naturally see more buckets on these irrespective of your replication activities.
Similarly it's also possible that firewalls might be blocking the forwarder access to some of your indexers (again depends on your env) causing the same issue. If you have set up custom load balancing on your forwarders, it can also cause this... there might be other similar reasons.. but you get the idea.

View solution in original post

0 Karma

Yasaswy
Contributor

Hi,
Buckets are not just limited to replication activity, they also include data being received. Depending on your deployment and how your forwarders are configured it's possible that some of your systems are forwarding to only few of the indexers in your cluster causing them to have higher bucket counts. Eg: if you have a cluster of 8 indexers with a replication factor of 2, but some of the forwarders in your environment are only set to forward to 3 of these, you will naturally see more buckets on these irrespective of your replication activities.
Similarly it's also possible that firewalls might be blocking the forwarder access to some of your indexers (again depends on your env) causing the same issue. If you have set up custom load balancing on your forwarders, it can also cause this... there might be other similar reasons.. but you get the idea.

0 Karma

daniel_augustyn
Contributor

Thanks --

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...