Yesterday one of our production indexer stopped indexing for 12 hours. Support found the cause to be a corrupt bucket.
The message in splunkd.log
was -
splunkd.log.2:02-03-2018 07:28:50.526 -0600 INFO HotBucketRoller - Bucket='/SplunkIndexData/splunk-indexes/<index name>/db/db_1517657319_1517657289_15604', idx=<index name>, newly --all **corrupt**: reason=''
I wonder why a corrupt bucket message, which causes the indexer to stop indexing, is marked only as INFO.