Getting Data In

Why do my indexers in my indexer clustering environment have a different number of buckets?

daniel_augustyn
Contributor

I just deployed Splunk in an indexer cluster deployment, and I've noticed that my indexers have a different number of buckets. Shouldn't they have the same number of buckets since the data is replicated? Or not all buckets get replicated between indexers?

0 Karma
1 Solution

Yasaswy
Contributor

Hi,
Buckets are not just limited to replication activity, they also include data being received. Depending on your deployment and how your forwarders are configured it's possible that some of your systems are forwarding to only few of the indexers in your cluster causing them to have higher bucket counts. Eg: if you have a cluster of 8 indexers with a replication factor of 2, but some of the forwarders in your environment are only set to forward to 3 of these, you will naturally see more buckets on these irrespective of your replication activities.
Similarly it's also possible that firewalls might be blocking the forwarder access to some of your indexers (again depends on your env) causing the same issue. If you have set up custom load balancing on your forwarders, it can also cause this... there might be other similar reasons.. but you get the idea.

View solution in original post

0 Karma

Yasaswy
Contributor

Hi,
Buckets are not just limited to replication activity, they also include data being received. Depending on your deployment and how your forwarders are configured it's possible that some of your systems are forwarding to only few of the indexers in your cluster causing them to have higher bucket counts. Eg: if you have a cluster of 8 indexers with a replication factor of 2, but some of the forwarders in your environment are only set to forward to 3 of these, you will naturally see more buckets on these irrespective of your replication activities.
Similarly it's also possible that firewalls might be blocking the forwarder access to some of your indexers (again depends on your env) causing the same issue. If you have set up custom load balancing on your forwarders, it can also cause this... there might be other similar reasons.. but you get the idea.

0 Karma

daniel_augustyn
Contributor

Thanks --

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...