<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IndexScopedSearch  deleting bad events? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/IndexScopedSearch-deleting-bad-events/m-p/129688#M26626</link>
    <description>&lt;P&gt;This may have nothing to do with indexed data corruption. If you had something that could generate 1,000 log events in a second, and if your timestamp is accurate only to the second, then all of those log entries would have the same epoch time (which is given in the error message for the frame of time where &amp;gt; 1,000,000 events have been seen). The epoch time is accurate to the millisecond, so in a single second you have 1,000 epoch times but only one is being used for all the events begin logged in any given second. Windows iis logs are by default accurate to the second. But you can google for your version and see about turning on millisecond time stamp. Whatever logs you are using, that's what I'd try.&lt;/P&gt;

&lt;P&gt;If this is being caused by corrupted data, there is quite a bit of information about dealing with that here: &lt;A href="http://wiki.splunk.com/Community:PostCrashFsckRepair"&gt;http://wiki.splunk.com/Community:PostCrashFsckRepair&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Feb 2015 23:21:34 GMT</pubDate>
    <dc:creator>wrangler2x</dc:creator>
    <dc:date>2015-02-06T23:21:34Z</dc:date>
    <item>
      <title>IndexScopedSearch  deleting bad events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/IndexScopedSearch-deleting-bad-events/m-p/129687#M26625</link>
      <description>&lt;P&gt;I'm getting the following error:&lt;BR /&gt;
Error in 'IndexScopedSearch': The search failed. More than 1000000 events found at time 1390985456.&lt;/P&gt;

&lt;P&gt;I found this existing question:&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/76392/how-to-delete-a-huge-number-of-old-events-from-the-test-data-that-has-slipped-in"&gt;http://answers.splunk.com/answers/76392/how-to-delete-a-huge-number-of-old-events-from-the-test-data-that-has-slipped-in&lt;/A&gt;&lt;BR /&gt;
as well as this one&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/119467/indexscopedsearch-error-while-searching"&gt;http://answers.splunk.com/answers/119467/indexscopedsearch-error-while-searching&lt;/A&gt;&lt;BR /&gt;
as well as this one&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/3397/indexscopedsearch-error-details"&gt;http://answers.splunk.com/answers/3397/indexscopedsearch-error-details&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I tried removing the db directories and restarting splunk. Still getting same error. I tried this command:&lt;BR /&gt;
_time="1389689456" | delete&lt;/P&gt;

&lt;P&gt;Does anyone know how to remove the bad data?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 19:28:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/IndexScopedSearch-deleting-bad-events/m-p/129687#M26625</guid>
      <dc:creator>jalfrey</dc:creator>
      <dc:date>2014-01-29T19:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: IndexScopedSearch  deleting bad events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/IndexScopedSearch-deleting-bad-events/m-p/129688#M26626</link>
      <description>&lt;P&gt;This may have nothing to do with indexed data corruption. If you had something that could generate 1,000 log events in a second, and if your timestamp is accurate only to the second, then all of those log entries would have the same epoch time (which is given in the error message for the frame of time where &amp;gt; 1,000,000 events have been seen). The epoch time is accurate to the millisecond, so in a single second you have 1,000 epoch times but only one is being used for all the events begin logged in any given second. Windows iis logs are by default accurate to the second. But you can google for your version and see about turning on millisecond time stamp. Whatever logs you are using, that's what I'd try.&lt;/P&gt;

&lt;P&gt;If this is being caused by corrupted data, there is quite a bit of information about dealing with that here: &lt;A href="http://wiki.splunk.com/Community:PostCrashFsckRepair"&gt;http://wiki.splunk.com/Community:PostCrashFsckRepair&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 23:21:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/IndexScopedSearch-deleting-bad-events/m-p/129688#M26626</guid>
      <dc:creator>wrangler2x</dc:creator>
      <dc:date>2015-02-06T23:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: IndexScopedSearch  deleting bad events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/IndexScopedSearch-deleting-bad-events/m-p/129689#M26627</link>
      <description>&lt;P&gt;See also my answer here: &lt;A href="http://answers.splunk.com/answers/81627/indexscopedsearch-error.html#answer-227648"&gt;http://answers.splunk.com/answers/81627/indexscopedsearch-error.html#answer-227648&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2015 21:06:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/IndexScopedSearch-deleting-bad-events/m-p/129689#M26627</guid>
      <dc:creator>wrangler2x</dc:creator>
      <dc:date>2015-04-14T21:06:34Z</dc:date>
    </item>
  </channel>
</rss>

