I'm running Splunk version 4.1.3 and am seeing a significant volume being reported in _thefishbucket index. This is confusing as my understanding is fishbucket is no longer an index as of Splunk version 4.x.
Currently this looks like a bug around the metrics monitoring, as no data should be written to _thefishbucket
index. It used to be used as the repository for keeping track of monitored file information, but has since been replaced by the btree
tracking method.
We'll update this again once we know exactly what's happening here
Currently this looks like a bug around the metrics monitoring, as no data should be written to _thefishbucket
index. It used to be used as the repository for keeping track of monitored file information, but has since been replaced by the btree
tracking method.
We'll update this again once we know exactly what's happening here
Rest assured that the volume reported as being indexed to _thefishbucket does NOT count against your license.