Splunk Enterprise

Indexes hotwarm disk space does not match in 4 nodes cluster

cannana
New Member

Hi,

I am new to Splunk and inherited the infrastructure. I noticed the bucket creation keeps failing and the hot warm file system on one site is in 70% and on the other site 90% - can anyone help, please?

Thank you

Labels (1)
0 Karma

codebuilder
SplunkTrust
SplunkTrust

In Splunk, buckets are constantly being created and removed as new data comes in and older data ages out into other buckets. Many factors influence how this occurs, from the amount of data coming in, to index and file system configurations in Splunk, and so on. What you are seeing is expected behavior.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...