Deployment Architecture

Unequal number of Buckets in indexer clustering.

motkarnaresh
Explorer

We have two indexers in our cluster and RF and SF are met. But the total number of buckets in one of the indexer is reducing day by day. present situation is, one indexer contain 25000 Buckets and other contain 5000 Buckets. Did anyone faced this type of situation? Please help me whether is this normal or need to worry?

0 Karma

ddrillic
Ultra Champion

It's interesting to see your view of the Indexer Clustering: Master Node

0 Karma

horsefez
SplunkTrust
SplunkTrust

Hi motkarnaresh,

looks wierd to me. I also administer a indexer cluster and I'm used to seeing diffences in bucket count aswell, but nothing that looks this extreme.

How much data are you indexing on average per day?
As TStrauch said, whats your RF?

What you could do for troubleshooting is following this documentation to list excess buckets.
https://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Removeextrabucketcopies

Don't remove them yet, just maybe show us the results of the splunk list excess-buckets command.

0 Karma

motkarnaresh
Explorer

Hi Pyro_wood,

There is nothing in excess-buckets list. Our SF=2 and RF=2 and we have only two indexers.
Our Splunk version is 6.3.1

0 Karma

TStrauch
Communicator

What is your search and replication faktor?

0 Karma

motkarnaresh
Explorer

SF=2 and RF=2 and we have two indexers.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...