<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I getting the following error while doing a search: &amp;quot;The limit has been reached for log messages&amp;quot; in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Why-am-I-getting-the-following-error-while-doing-a-search-quot/m-p/571862#M24946</link>
    <description>&lt;P&gt;I am also getting this error. we have found this stanza on both indexer and search head. Where do I need to increase the value of&amp;nbsp;max_infocsv_messages.&lt;/P&gt;&lt;P&gt;[search_info]&lt;BR /&gt;# These setting control logging of error messages to info.csv&lt;BR /&gt;# All messages will be logged to search.log regardless of these settings.&lt;BR /&gt;# maximum number of error messages to log in info.csv&lt;BR /&gt;# Set to 0 to remove limit, may affect search performance&lt;BR /&gt;max_infocsv_messages = 20&lt;BR /&gt;# log level = DEBUG | INFO | WARN | ERROR&lt;BR /&gt;infocsv_log_level = INFO&lt;BR /&gt;# Log warnings if search returns no results because user has no&lt;BR /&gt;# permissions to search on queried indexes.&lt;BR /&gt;show_warn_on_filtered_indexes = false&lt;BR /&gt;# Log level of messages when search returns no results because user has&lt;BR /&gt;# no permissions to search on queried indexes.&lt;BR /&gt;filteredindexes_log_level = DEBUG&lt;/P&gt;</description>
    <pubDate>Thu, 21 Oct 2021 16:54:37 GMT</pubDate>
    <dc:creator>rohit2301kumar</dc:creator>
    <dc:date>2021-10-21T16:54:37Z</dc:date>
    <item>
      <title>Why am I getting the following error while doing a search: "The limit has been reached for log messages"</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-am-I-getting-the-following-error-while-doing-a-search-quot/m-p/442975#M21217</link>
      <description>&lt;P&gt;For 1 week search.  It gets to 20,306 of 35,215 events matched and then it gets stuck and gives the following error : &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;The limit has been reached for log messages in info.csv. 35 messages have not been written to info.csv. Please refer to search.log for these messages or limits.conf to configure this limit.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 20 Dec 2018 19:20:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-am-I-getting-the-following-error-while-doing-a-search-quot/m-p/442975#M21217</guid>
      <dc:creator>srampally</dc:creator>
      <dc:date>2018-12-20T19:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting the following error while doing a search: "The limit has been reached for log messages"</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-am-I-getting-the-following-error-while-doing-a-search-quot/m-p/442976#M21218</link>
      <description>&lt;P&gt;You can change a parameter in the &lt;CODE&gt;limits.conf&lt;/CODE&gt; file to get rid of this error, but you will have to make thew value high enough to keep it from giving you the error. Don't make it too high, but enough to fix your problem. The value, I believe, is &lt;CODE&gt;max_infocsv_message&lt;/CODE&gt; and the default is something like 20. In your case I'd set it to 50, but you may have to experiment. Look at the limits.conf documentation to make sure you are doing it all correctly:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.1/Admin/Limitsconf"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.1/Admin/Limitsconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 22:39:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-am-I-getting-the-following-error-while-doing-a-search-quot/m-p/442976#M21218</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2018-12-20T22:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting the following error while doing a search: "The limit has been reached for log messages"</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-am-I-getting-the-following-error-while-doing-a-search-quot/m-p/571862#M24946</link>
      <description>&lt;P&gt;I am also getting this error. we have found this stanza on both indexer and search head. Where do I need to increase the value of&amp;nbsp;max_infocsv_messages.&lt;/P&gt;&lt;P&gt;[search_info]&lt;BR /&gt;# These setting control logging of error messages to info.csv&lt;BR /&gt;# All messages will be logged to search.log regardless of these settings.&lt;BR /&gt;# maximum number of error messages to log in info.csv&lt;BR /&gt;# Set to 0 to remove limit, may affect search performance&lt;BR /&gt;max_infocsv_messages = 20&lt;BR /&gt;# log level = DEBUG | INFO | WARN | ERROR&lt;BR /&gt;infocsv_log_level = INFO&lt;BR /&gt;# Log warnings if search returns no results because user has no&lt;BR /&gt;# permissions to search on queried indexes.&lt;BR /&gt;show_warn_on_filtered_indexes = false&lt;BR /&gt;# Log level of messages when search returns no results because user has&lt;BR /&gt;# no permissions to search on queried indexes.&lt;BR /&gt;filteredindexes_log_level = DEBUG&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 16:54:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-am-I-getting-the-following-error-while-doing-a-search-quot/m-p/571862#M24946</guid>
      <dc:creator>rohit2301kumar</dc:creator>
      <dc:date>2021-10-21T16:54:37Z</dc:date>
    </item>
  </channel>
</rss>

