Splunk Cloud Platform

Health status showing critical in CMC due to small bucket count.

vishenps1
New Member

I was doing regular health checks in my Splunk deployment and found In indexing health is critical mainly due to the small bucket count, maxbucketSize has been set to auto, not sure what else might be the cause

I'm new to the org and have little or no idea about the underlying architecture and implementation. 

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

One reason for that is bad timestamp handling or data from different times to one index. There should be some previous posts about it on community.

r. Ismo

Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...