Monitoring Splunk

How to fix "Percentage of small buckets is high"?

uagraw01
Motivator

I am getting below error from Splunkd. How to fix this root cause error. Please suggest some workaround.

 

uagraw01_0-1700669009004.png

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

This said that small bucket count in _internal is 4, which is not so high. 

Have you any reason why this has happened e.g. some reboot service/server or other reason why those buckets has roll over from hot to warm?

Anyhow you must know why those buckets has rolled before you could fix the issue? Some possible reasons could be:

  • reboot splunk
  • manually rolled those
  • bad data (e.g. time stamp issues)
  • you reinvesting old and new log files / data at same time

r. Ismo

uagraw01
Motivator

@isoutamo For now simple restart of splunkd fixed my issue.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...