Deployment Architecture

How to fix bucket replication issues?

brent_weaver
Builder

I am unable to search my indexed data from now in splunk. We have a rather large env, 53 indexers. I am seeing that there are prending_build. How to I rememdy this situation?

FBD33A23-C500-47E3-9E82-0AB11F56AB35
        active_bundle_id:D260DA9609DA32CC4A51CA307BEA131E
        base_generation_id:130560
        bucket_count:1910
        delayed_buckets_to_discard:
        fixup_set:
        heartbeat_started:1
        host_port_pair:10.9.1.9:8089
        indexing_disk_space:13191985758208
        is_searchable:1
        is_valid_bundle:1
        label:ip-10-9-1-9
        last_heartbeat:1517090749
        last_validated_bundle:D260DA9609DA32CC4A51CA307BEA131E
        latest_bundle_id:D260DA9609DA32CC4A51CA307BEA131E
        pending_builds:
            us_west_prod_predix_firehose~779~51A2E4CB-11EA-4585-84C7-D31FA864754C
        pending_job_count:0
        primary_count:1266
        primary_count_remote:1286
        register_search_address:10.9.1.9:8089
        replication_count:0
        replication_port:9887
        replication_use_ssl:0
        site:site2
        status:Up
        summary_replication_count:0
Tags (1)
0 Karma

HiroshiSatoh
Champion

If it is a temporary replication problem time will be resolved.

What is the load situation of each indexer? Is the load biased on one?

In a clustered environment I know, there was a case in which loading concentrated on one indexer due to one huge log, making searching impossible.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...