I was doing regular health checks in my Splunk deployment and found In indexing health is critical mainly due to the small bucket count, maxbucketSize has been set to auto, not sure what else might be the cause.
I'm new to the org and have little or no idea about the underlying architecture and implementation.
Hi
One reason for that is bad timestamp handling or data from different times to one index. There should be some previous posts about it on community.
r. Ismo