Hello,
Recently I been getting Bucket error in index processor everyday. I am rebooting the Splunkd service everyday to get rid of this error.
How to identify the root cause of this issue and fix it.
error attached
Thanks
Can you click item “Bucket” to get the details of error and also look what you can found from internal logs (e.g. index=_internal sourcetype=splunkd bucket)?
r. Ismo
Can you click item “Bucket” to get the details of error and also look what you can found from internal logs (e.g. index=_internal sourcetype=splunkd bucket)?
r. Ismo
Hello,
I get a response with one of my index
"Root Cause(s):
The percentage of small of buckets created (100) over the last hour is very high and exceeded the red thresholds (50) for index=jenkins_statistics, and possibly more indexes, on this indexer"
Any idea how to fix this issue.
Hi
if you don’t use smartstore then you should update your indexes.conf with maxDataSize = auto_high_volume for that index if this behavior is regular.
r. Ismo