Deployment Architecture

Different number of buckets

Dias
Explorer

Hi, I have an issue in indexer cluster. It's been a month since i noticed there are different number of buckets in two indexers.  Search factor, Replication factor fine. What is the reason for this difference? tempsnip.png

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

The easiest way is use the next command on cli.

splunk btool indexes list --debug|egrep '(\[|repFa)'|egrep -A1 '\[_'

It also shows where those values comes (usually .../system/default/indexes.conf unless you have changed those). If you need to change these, then the best option is create separate app for those changes.

r. Ismo

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Have you check that those are not excess buckets?
r. Ismo
0 Karma

Dias
Explorer

I checked the bucket status and there are no excess buckets.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Are all your indexes replicated over cluster, including internal indexes (repFactor = auto) ?

0 Karma

Dias
Explorer

I checked the indexes and it is "repFactor=auto"everywhere. Do you know where to check for internal indexes repFactor?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

The easiest way is use the next command on cli.

splunk btool indexes list --debug|egrep '(\[|repFa)'|egrep -A1 '\[_'

It also shows where those values comes (usually .../system/default/indexes.conf unless you have changed those). If you need to change these, then the best option is create separate app for those changes.

r. Ismo

0 Karma

Dias
Explorer

Thanks for the answer, I've checked the internal indexes. And there were those in which repFactor=0. I changed it to repFactor=auto.  Your CLI command helped a lot, thanks again.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...