Monitoring Splunk

Splunk bucket size analysis

jinx
New Member

Issue:
Buckets health indicator reports gigantic warm bucket for _metrics,
but the settled warm bucket is approximately 10 GiB. splunk enterprise 10.0.2 , indexer cluster with a search head was join to the indexer cluster. i have warning for _metric bucket more than 20GB.

Configuration:
datatype=metric
maxDataSize=auto_high_volume
metric.stubOutRawdataJournal=true
repFactor=0

Example: Indexer-02, bucket 337

HotBucketRoller:
bid=_metrics~337~5218DBAE-3E56-44C9-8729-872CF04D2A87
size=21993381888
caller=size_exceeded
_maxHotBucketSize=10737418240
bucketSize=10737451008

PeriodicHealthReporter:
gigantic_bucket_size
bucket_size=21993381888
yellow_size_threshold=20971520000

After rollover:

dbinspect:
bucket=337
state=warm
sizeOnDiskMB=10269.71
sizeGiB=10.029

Filesystem:
du -sh bucket/
11G

du -sh bucket/rawdata
12K

Observation:
The Health Reporter bucket_size is byte-for-byte identical to
HotBucketRoller's transient physical "size", but after
metric.stubOutRawdataJournal completes, the resulting warm bucket
is approximately 10 GiB.

Question:
Should the gigantic_bucket_size health check exclude the temporary
rawdata journal size for metric indexes where
metric.stubOutRawdataJournal=true?

Why does PeriodicHealthReporter continue reporting the same historical
23087370240 / 21993381888 values after the associated buckets have
settled to normal size?

Tags (2)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...