Monitoring Splunk

How to fix "Percentage of small buckets is high"?

uagraw01
Motivator

I am getting below error from Splunkd. How to fix this root cause error. Please suggest some workaround.

 

uagraw01_0-1700669009004.png

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

This said that small bucket count in _internal is 4, which is not so high. 

Have you any reason why this has happened e.g. some reboot service/server or other reason why those buckets has roll over from hot to warm?

Anyhow you must know why those buckets has rolled before you could fix the issue? Some possible reasons could be:

  • reboot splunk
  • manually rolled those
  • bad data (e.g. time stamp issues)
  • you reinvesting old and new log files / data at same time

r. Ismo

uagraw01
Motivator

@isoutamo For now simple restart of splunkd fixed my issue.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...