<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to avoid events not being returned in sub-second error? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-avoid-events-not-being-returned-in-sub-second-error/m-p/622122#M14614</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;getting following error in splunk:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;"Events may not be returned in sub-second order due to search memory limits . See search.log for more information. settings: [search]:max_rawsize_perchunk"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;when i am searching for paticular time range like : 4 to 8 i am getting this error.&lt;BR /&gt;but if i search for last 15 mins or 24 hours or last 7 days i am not getting the error.&lt;BR /&gt;&lt;BR /&gt;I understood : that between 4 to 8 timerange there where lot events coming for one second.&lt;BR /&gt;&lt;BR /&gt;1. below are my&amp;nbsp; props configured and sample logs:&lt;BR /&gt;&lt;BR /&gt;20221012453012&lt;BR /&gt;20220812453012&lt;BR /&gt;20220912453012&lt;BR /&gt;20220612453012&lt;BR /&gt;H1S98765~~PR~;R ESC~AB~Thu Oct 12 12:34:56 IST 2022~B~1.22~2.22~3456.98~GF~4356BV&lt;BR /&gt;H1S98765~~PR~;Z ESC~AB~Thu Oct 12 12:34:56 IST 2022~B~1.22~2.22~3456.98~GF~4356BV&lt;BR /&gt;H1S98765~~PR~;M ESC~AB~Thu Oct 12 12:34:56 IST 2022~B~1.22~2.22~3456.98~GF~4356BV&lt;BR /&gt;H1S98765~~PR~;T ESC~AB~Thu Oct 12 12:34:56 IST 2022~B~1.22~2.22~3456.98~GF~4356BV&lt;BR /&gt;&lt;BR /&gt;[logs:health:app]&lt;BR /&gt;truncate=10000&lt;BR /&gt;time_prefix=(?:[^~]+~)~(?:[^~]+~){3}&lt;BR /&gt;time_format=%a %b %d %H: %M: %S&amp;nbsp; %Z&lt;BR /&gt;disable=false&lt;BR /&gt;max_timestamp_lookahead=75&lt;BR /&gt;charset=UFT_8&lt;BR /&gt;no_binary_check=true&lt;BR /&gt;datetime_config=CURRENT&lt;BR /&gt;should_linenerge=false&lt;BR /&gt;line_breaker=([\r\n]+)\w{8}~~&lt;BR /&gt;annotate_punct=false&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp;below are my&amp;nbsp; props configured and sample logs:&lt;BR /&gt;[10/07/22 12:55:40"7451 IST] 89786545 medapplog&amp;nbsp; 9[10/07/22 12:55:40"7451 IST-897654] [app=med, sucees=0, failed=10, validpoints=100]&amp;nbsp; the events are assocuiated with the med application user=app client=med&lt;BR /&gt;[08/07/22 12:55:40"7451 IST] 89786545 medapplog&amp;nbsp; 9[10/07/22 12:55:40"7451 IST-897654] [app=med, sucees=0, failed=10, validpoints=100]&amp;nbsp; the events are assocuiated with the med application user=app client=med&lt;BR /&gt;[10/12/22 12:55:40"7451 IST] 89786545 medapplog&amp;nbsp; 9[10/07/22 12:55:40"7451 IST-897654] [app=med, sucees=0, failed=10, validpoints=100]&amp;nbsp; the events are assocuiated with the med application user=app client=med&lt;BR /&gt;&lt;BR /&gt;[logs:med:app]&lt;BR /&gt;time_prefix=^\[&lt;BR /&gt;time_format=%m %d %y&amp;nbsp; %H: %M: %S: %3Q&amp;nbsp; %Z&lt;BR /&gt;max_timestamp_lookahead=30&lt;BR /&gt;should_linenerge=false&lt;BR /&gt;line_breaker=([\r\n]+)\[\d{1,2}\/\d{1,2}\/\d{2}\s\d{1,2}:\d{2}:\d{2}:\d{3}\s\D{3}\]&lt;BR /&gt;truncate=99999&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;please let me know how to avoid this error coming when i search.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 27 Nov 2022 16:16:05 GMT</pubDate>
    <dc:creator>mahesh27</dc:creator>
    <dc:date>2022-11-27T16:16:05Z</dc:date>
    <item>
      <title>How to avoid events not being returned in sub-second error?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-avoid-events-not-being-returned-in-sub-second-error/m-p/622122#M14614</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;getting following error in splunk:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;"Events may not be returned in sub-second order due to search memory limits . See search.log for more information. settings: [search]:max_rawsize_perchunk"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;when i am searching for paticular time range like : 4 to 8 i am getting this error.&lt;BR /&gt;but if i search for last 15 mins or 24 hours or last 7 days i am not getting the error.&lt;BR /&gt;&lt;BR /&gt;I understood : that between 4 to 8 timerange there where lot events coming for one second.&lt;BR /&gt;&lt;BR /&gt;1. below are my&amp;nbsp; props configured and sample logs:&lt;BR /&gt;&lt;BR /&gt;20221012453012&lt;BR /&gt;20220812453012&lt;BR /&gt;20220912453012&lt;BR /&gt;20220612453012&lt;BR /&gt;H1S98765~~PR~;R ESC~AB~Thu Oct 12 12:34:56 IST 2022~B~1.22~2.22~3456.98~GF~4356BV&lt;BR /&gt;H1S98765~~PR~;Z ESC~AB~Thu Oct 12 12:34:56 IST 2022~B~1.22~2.22~3456.98~GF~4356BV&lt;BR /&gt;H1S98765~~PR~;M ESC~AB~Thu Oct 12 12:34:56 IST 2022~B~1.22~2.22~3456.98~GF~4356BV&lt;BR /&gt;H1S98765~~PR~;T ESC~AB~Thu Oct 12 12:34:56 IST 2022~B~1.22~2.22~3456.98~GF~4356BV&lt;BR /&gt;&lt;BR /&gt;[logs:health:app]&lt;BR /&gt;truncate=10000&lt;BR /&gt;time_prefix=(?:[^~]+~)~(?:[^~]+~){3}&lt;BR /&gt;time_format=%a %b %d %H: %M: %S&amp;nbsp; %Z&lt;BR /&gt;disable=false&lt;BR /&gt;max_timestamp_lookahead=75&lt;BR /&gt;charset=UFT_8&lt;BR /&gt;no_binary_check=true&lt;BR /&gt;datetime_config=CURRENT&lt;BR /&gt;should_linenerge=false&lt;BR /&gt;line_breaker=([\r\n]+)\w{8}~~&lt;BR /&gt;annotate_punct=false&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp;below are my&amp;nbsp; props configured and sample logs:&lt;BR /&gt;[10/07/22 12:55:40"7451 IST] 89786545 medapplog&amp;nbsp; 9[10/07/22 12:55:40"7451 IST-897654] [app=med, sucees=0, failed=10, validpoints=100]&amp;nbsp; the events are assocuiated with the med application user=app client=med&lt;BR /&gt;[08/07/22 12:55:40"7451 IST] 89786545 medapplog&amp;nbsp; 9[10/07/22 12:55:40"7451 IST-897654] [app=med, sucees=0, failed=10, validpoints=100]&amp;nbsp; the events are assocuiated with the med application user=app client=med&lt;BR /&gt;[10/12/22 12:55:40"7451 IST] 89786545 medapplog&amp;nbsp; 9[10/07/22 12:55:40"7451 IST-897654] [app=med, sucees=0, failed=10, validpoints=100]&amp;nbsp; the events are assocuiated with the med application user=app client=med&lt;BR /&gt;&lt;BR /&gt;[logs:med:app]&lt;BR /&gt;time_prefix=^\[&lt;BR /&gt;time_format=%m %d %y&amp;nbsp; %H: %M: %S: %3Q&amp;nbsp; %Z&lt;BR /&gt;max_timestamp_lookahead=30&lt;BR /&gt;should_linenerge=false&lt;BR /&gt;line_breaker=([\r\n]+)\[\d{1,2}\/\d{1,2}\/\d{2}\s\d{1,2}:\d{2}:\d{2}:\d{3}\s\D{3}\]&lt;BR /&gt;truncate=99999&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;please let me know how to avoid this error coming when i search.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Nov 2022 16:16:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-avoid-events-not-being-returned-in-sub-second-error/m-p/622122#M14614</guid>
      <dc:creator>mahesh27</dc:creator>
      <dc:date>2022-11-27T16:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: Events might not be returned in sub-second error</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-avoid-events-not-being-returned-in-sub-second-error/m-p/622174#M14616</link>
      <description>&lt;P&gt;This happens when more than 100MB of search results with the same timestamp are found.&amp;nbsp; How does that happen?&amp;nbsp; Either 1) all (or a lot) of your data has the same timestamp; or 2) it has no timestamp and Splunk assigns the same timestamp to it; or 3) the props.conf settings are incorrect, leading Splunk to assign the same wrong timestamp to all or a lot of the data.&amp;nbsp; In this case, the answer appears to be #3 (with some #2).&lt;/P&gt;&lt;P&gt;Of course, that could change based on what is in search.log.&lt;/P&gt;&lt;P&gt;Let's look at log #1.&lt;/P&gt;&lt;P&gt;Half of the sample events are just digits that might be a timestamp.&amp;nbsp; The other half contain a timestamp, but the props are a little off.&amp;nbsp; Try these (replacing only those mentioned below).&amp;nbsp; (FWIW, I always specify props.conf settings in upper case.)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME_PREFIX = (.*?~){5}
TIME_FORMAT = %a %b %d %H:%M:%S %Z %Y&lt;/LI-CODE&gt;&lt;P&gt;Log #2 is similar.&amp;nbsp; The TIME_FORMAT setting does not match the sample data.&amp;nbsp; Try this one&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME_FORMAT = %m/%d/%y %H:%M:%S"%4N %Z&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Nov 2022 01:38:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-avoid-events-not-being-returned-in-sub-second-error/m-p/622174#M14616</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-11-27T01:38:44Z</dc:date>
    </item>
  </channel>
</rss>

