Deployment Architecture

Modify Splunk health checks - The percentage of small buckets created over the last hour is high

_joe
Communicator

Hello all,

Looking for a way to modify the Splunk Health Check for small buckets. Specifically, I would like the healthcheck to exclude certain indexes.

For example, I like knowing if I am getting too many small buckets... but not if it is for my test index.

 Buckets

  • Root Cause(s):
    • The percentage of small buckets (100%) created over the last hour is high and exceeded the red thresholds (50%) for index=test, and possibly more indexes, on this indexer. At the time this alert fired, total buckets created=6, small buckets=6
    • The percentage of small buckets (100%) created over the last hour is high and exceeded the red thresholds (50%) for index=test, and possibly more indexes, on this indexer. At the time this alert fired, total buckets created=5, small buckets=5
Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I was looking into this today for a similar problem with a different health check.  It turns out we can adjust the threshold for when the check turns yellow or red, but can't change the check itself.  IOW, the search is hardcoded.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...