Knowledge Management

Any experience/practices with old buckets getting created with sourcetype config_file?



I have an index (index=config) where all I store are the sourcetype=config_file. I currently use the stock config from Splunk_TA_nix. 

What I am thinking is happening is that when we provision new server the config_files are often dated in years old so Splunk is creating new bucked dated years old. Is that reasonable assumption? 

Looking at btool I am thinking all I need to do is set MAX_DAYS_AGO = 1 from 2000. 

Here is the error message I am seeing The percentage of small buckets (100%) created over the last hour is high and exceeded the red thresholds (50%) for index=configs, and possibly more indexes, on this indexer. At the time this alert fired, total buckets created=4, small buckets=4

Any other input or best practices around indexing config_files? 

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

<P style=" text-align: center; "><span class="lia-inline-image-display-wrapper lia-image-align-center" ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

<FONT size="5"><FONT size="5" color="#FF00FF">Get the latest news and updates from the Splunk Community ...