Monitoring Splunk

How to fix "Percentage of small buckets is high"?

uagraw01
Motivator

I am getting below error from Splunkd. How to fix this root cause error. Please suggest some workaround.

 

uagraw01_0-1700669009004.png

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

This said that small bucket count in _internal is 4, which is not so high. 

Have you any reason why this has happened e.g. some reboot service/server or other reason why those buckets has roll over from hot to warm?

Anyhow you must know why those buckets has rolled before you could fix the issue? Some possible reasons could be:

  • reboot splunk
  • manually rolled those
  • bad data (e.g. time stamp issues)
  • you reinvesting old and new log files / data at same time

r. Ismo

uagraw01
Motivator

@isoutamo For now simple restart of splunkd fixed my issue.

Tags (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...