Getting Data In

Unexpected failure to parse bucket (5.0.3 indexer)

the_wolverine
Champion

I'm seeing a lot of these WARNs reported by indexer and would like to know what it means:

03-12-2014 17:57:38.135 +0000 WARN
BucketMover - Unexpected failure to
parse
bucket='/opt/splunk/var/lib/splunk/main/db/hot_v1_3656'

0 Karma

jrodman
Splunk Employee
Splunk Employee

This warning is correct but pointless for a hot bucket. If Splunk incorrectly attempts to parse hot buckets for the time endpoints in some cases, then numbers which indicate the oldest and newest times of the bucket are not available to be parsed. In other words, for hot buckets, attempting to parse the names will produce this warning.

My best information (grain of salt here) suggests that we are not currently aware of the reasons why Splunk would parse hot buckets, and we have not been able to produce the problem via any means in Splunk 6.1.

It might be advisable to manually investigate these buckets and see if there's anything unusual about them (missing, truncated files, etc.) that would lead to a problem needing further investigation by Splunk. However it could be that this is just a messaging problem was fixed by changes not specifically targetted at this message between early 5.0.x and 6.1.

More information is welcome.

the_wolverine
Champion

Super appreciate your response, Jrodman.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...