Monitoring Splunk

How to fix "Percentage of small buckets is high"?

uagraw01
Motivator

I am getting below error from Splunkd. How to fix this root cause error. Please suggest some workaround.

 

uagraw01_0-1700669009004.png

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

This said that small bucket count in _internal is 4, which is not so high. 

Have you any reason why this has happened e.g. some reboot service/server or other reason why those buckets has roll over from hot to warm?

Anyhow you must know why those buckets has rolled before you could fix the issue? Some possible reasons could be:

  • reboot splunk
  • manually rolled those
  • bad data (e.g. time stamp issues)
  • you reinvesting old and new log files / data at same time

r. Ismo

uagraw01
Motivator

@isoutamo For now simple restart of splunkd fixed my issue.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...