Splunk Enterprise

Indexes hotwarm disk space does not match in 4 nodes cluster

cannana
New Member

Hi,

I am new to Splunk and inherited the infrastructure. I noticed the bucket creation keeps failing and the hot warm file system on one site is in 70% and on the other site 90% - can anyone help, please?

Thank you

Labels (1)
0 Karma

codebuilder
Influencer

In Splunk, buckets are constantly being created and removed as new data comes in and older data ages out into other buckets. Many factors influence how this occurs, from the amount of data coming in, to index and file system configurations in Splunk, and so on. What you are seeing is expected behavior.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...