Deployment Architecture

Different number of buckets on cluster

Path Finder

Hello all,

I have a "problem" with a new indexer added in my cluster.
My cluster has two indexers.
The goal is to replace these two indexers by two other with more resources.

So here what I did:

1) realize all the configurations in indexes.conf, server.conf etc
2) add the new indexer in my cluster
3) shut down and remove from the cluster the old indexer
4) wait for the replication finishing.

The problem is that, once replication finished, I have an important number of buckets that missing.
My new server in the cluster has 9500 buckets and the old one, 11500.

When I launch a research for the same time period on the same index but on the new and the second old server, I don't have the same number of results.

I tried the "data rebalance" but nothing...everything is green in the Master node under Indexer clustering.

Is there anyway to force the missing bucket replication?

edit: I've just realized that the problem was already there before the addition of the new server. The removed server has lowest bucket number and lower events in the indexes.

Thank you in advance.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...

Admin Console: A Single, Unified Interface for All Your Cloud Admin Needs

WATCH NOWJoin us to learn how the admin console can save you time and give you more control over the Splunk® ...