I have splunk cluster with sf=2, rf=2 (they are met).
It was maintained by another contractor, so I have no ideas about what caused the issue.
First, on master node for some indexes I see data copies marked grey and data copies number is 170/173, etc... same for serachable and replicated copies. And no bucket fixup tasks are running.
I guess this means that some buckets do not exist on both indexers, am I right?
Second, I ran dbinspect command for this index, it returned 173 results. tsidxState is "full" for every bucket.
How do I find problematic buckets and delete them to make Indexer clustering page green again?
UPD. I uploaded photo
... View more