Splunk Enterprise

Some data is not searchable in index

yasir
Observer

After a rolling restart of peer nodes one index is not fully searchable . It seems fixup status is pending 

looks like buckets is not properly sync  .   need help to sort it out cluster.png

Labels (1)
0 Karma

PaulPanther
Builder

Have you tried to resync the bucket under Actions?

0 Karma

yasir
Observer

Yes, it’ not worked 

0 Karma

PaulPanther
Builder

Okay, could you please check out following thread Solved: How to resolve index buckets stuck in "Fixup Tasks... - Splunk Community and follow the described steps?

0 Karma

yasir
Observer

Yes, i followed the steps . But its not worked in this case 

Still showing below reason

bucket fix up.jpg

0 Karma
Get Updates on the Splunk Community!

New Case Study Shows the Value of Partnering with Splunk Academic Alliance

The University of Nevada, Las Vegas (UNLV) is another premier research institution helping to shape the next ...

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...