Deployment Architecture

Different number of buckets on cluster

mvagionakis
Path Finder

Hello all,

I have a "problem" with a new indexer added in my cluster.
My cluster has two indexers.
The goal is to replace these two indexers by two other with more resources.

So here what I did:

1) realize all the configurations in indexes.conf, server.conf etc
2) add the new indexer in my cluster
3) shut down and remove from the cluster the old indexer
4) wait for the replication finishing.

The problem is that, once replication finished, I have an important number of buckets that missing.
My new server in the cluster has 9500 buckets and the old one, 11500.

When I launch a research for the same time period on the same index but on the new and the second old server, I don't have the same number of results.

I tried the "data rebalance" but nothing...everything is green in the Master node under Indexer clustering.

Is there anyway to force the missing bucket replication?

edit: I've just realized that the problem was already there before the addition of the new server. The removed server has lowest bucket number and lower events in the indexes.

Thank you in advance.
Michael

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...