Hello,
Recently I been getting Bucket error in index processor everyday. I am rebooting the Splunkd service everyday to get rid of this error.
How to identify the root cause of this issue and fix it.
error attached
gowtham08091_0-1594445795696.png
Thanks
Can you click item “Bucket” to get the details of error and also look what you can found from internal logs (e.g. index=_internal sourcetype=splunkd bucket)?
r. Ismo
Can you click item “Bucket” to get the details of error and also look what you can found from internal logs (e.g. index=_internal sourcetype=splunkd bucket)?
r. Ismo
Hello,
I get a response with one of my index
"Root Cause(s):
The percentage of small of buckets created (100) over the last hour is very high and exceeded the red thresholds (50) for index=jenkins_statistics, and possibly more indexes, on this indexer"
Any idea how to fix this issue.
Hi
if you don’t use smartstore then you should update your indexes.conf with maxDataSize = auto_high_volume for that index if this behavior is regular.
r. Ismo