Splunk Enterprise

Replicated Buckets from Previous Install

u788332
New Member

This question is related to previous case 130465

After several issue with Hot and Warm bucket space I had to rebuild my cluster and in rebuilding I didn't realize that there was a unique reference per index so the new rebuild took new references per index. It has all been working, however, I now notice that the replicas, which are housed in the cold bucket volume location are not being rolled off as they appear to be named to the old index references

Peer 41v
OLD guid = 52CC719A-74AE-4400-9B2B-8B5807659408
NEW guid = 473195B7-3F01-433F-A4C4-EDCC948F1952

Peer 43v
OLD guid = A28F6DF7-1389-44BA-A20C-FE706296EA10
NEW guid = A3E51F2F-D379-4BB4-BFF0-C0E22875BF73

Number of buckets replicas in Cold on Peer 41v
502 52CC719A-74AE-4400-9B2B-8B5807659408
805 A28F6DF7-1389-44BA-A20C-FE706296EA10
28 A3E51F2F-D379-4BB4-BFF0-C0E22875BF73

Number of buckets replicas in Cold on Peer 43v
502 52CC719A-74AE-4400-9B2B-8B5807659408
805 A28F6DF7-1389-44BA-A20C-FE706296EA10
40 473195B7-3F01-433F-A4C4-EDCC948F1952

As you can see there 502 and 805 associated with the old index references. I can search the data, which is useful but the volume is filling up and as these buckets don't appear to be being removed I believe I will hit an issue.

Will Splunk recognize these replicas and remove them even though they have the old index references, or do I have to manually delete them?

Tags (4)
0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

The cluster may not recognize the old references, so it has to be manually removed.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

Happy CX Day, Splunk Community!

Happy CX Day, Splunk Community! CX stands for Customer Experience, and today, October 3rd, is CX Day — a ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...