...aking the time the search was running in, I got the epoch time and figured-out whatbucket was involved. I then used 'splunk rebuild' to rebuild the bucket (with splunkd stopped). Here is the r...
...howing as Index Processor>Bucketswith root cause "The percentage of small buckets (71%) created over the last hour is high and exceeded the red thresholds (50%) for index=os, and possibly more indexes, o...
Just helped Support with this and want to document the results...
Let's say that I've indexed an S3 bucket, and realized that my line breakers were wrong and I need to reindex... well, I've got a...
Hello fellow Splunkers,
I am trying to get to the bottom of issue I am having on an index cluster, specifically around hot buckets rolling before they should. I have read all of the docs around t...
I have Clustered Spunk environment (also called as bucket replication) with
--One Cluster Master
--Five cluster Peers
--Search Head.
One of our Cluster Peer ran out of Disk Space for p...
...re numerical) of each field with 2 samples. One for the events from -2h@h to -1h@h and another from -1h@h to @h
Whatido get is 31 results.
Same result when using 'bins=2'
When using 'minspan=1...
Hello there,
We faced an issue with our Indexer Cluster and I am trying to understand what happened.
I see these messages :
07-25-2018 11:51:02.387 +0200 WARN CMMaster - event=r...
...bsp;
So basically now DISABLED buckets could have more data (but not all the data) than the non disabled ones. Furthermore non disabled ones have been replicated within the cluster.
Do you think there i...
...x, there are six buckets: 10:00, 10:02 ... 10:10, with the first and last bucket containing one minutes' worth of data each (half the data).
WhatI think should happen with the 10:11 search is f...
....
The backup guidelines state "hot bucket - Currently written to; non-incrementally changing; do not back this up." So, whatI'm trying to dois tune indexing policy to insure we move from h...