Hi,
I am new to Splunk and inherited the infrastructure. I noticed the bucket creation keeps failing and the hot warm file system on one site is in 70% and on the other site 90% - can anyone help, please?
Thank you
In Splunk, buckets are constantly being created and removed as new data comes in and older data ages out into other buckets. Many factors influence how this occurs, from the amount of data coming in, to index and file system configurations in Splunk, and so on. What you are seeing is expected behavior.