<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I getting &amp;quot;Error fetching event from search peer&amp;quot; when searching for a specific sourcetype? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-Error-fetching-event-from-search-peer-quot/m-p/140374#M38770</link>
    <description>&lt;P&gt;I added the query. But it was only sourcetype=mysourcetype. After this certain time, there are results shown.&lt;/P&gt;</description>
    <pubDate>Thu, 25 Sep 2014 12:43:42 GMT</pubDate>
    <dc:creator>yAlff</dc:creator>
    <dc:date>2014-09-25T12:43:42Z</dc:date>
    <item>
      <title>Why am I getting "Error fetching event from search peer" when searching for a specific sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-Error-fetching-event-from-search-peer-quot/m-p/140372#M38768</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
searching for a specific sourcetype I get the message&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;### ERROR FETCHING EVENT FROM SEARCH PEER ###
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What can I do with this error? It only occurs at a certain time range (before sept 24, 7 pm).&lt;BR /&gt;
Maybe someone has an idea about what this error tells me? I didn't find anything yet.&lt;/P&gt;

&lt;P&gt;The whole search query is &lt;CODE&gt;sourcetype=mysourcetype&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Best regards,&lt;BR /&gt;
Yannic&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2014 12:10:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-Error-fetching-event-from-search-peer-quot/m-p/140372#M38768</guid>
      <dc:creator>yAlff</dc:creator>
      <dc:date>2014-09-25T12:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "Error fetching event from search peer" when searching for a specific sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-Error-fetching-event-from-search-peer-quot/m-p/140373#M38769</link>
      <description>&lt;P&gt;Please paste your search that failed.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2014 12:37:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-Error-fetching-event-from-search-peer-quot/m-p/140373#M38769</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2014-09-25T12:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "Error fetching event from search peer" when searching for a specific sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-Error-fetching-event-from-search-peer-quot/m-p/140374#M38770</link>
      <description>&lt;P&gt;I added the query. But it was only sourcetype=mysourcetype. After this certain time, there are results shown.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2014 12:43:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-Error-fetching-event-from-search-peer-quot/m-p/140374#M38770</guid>
      <dc:creator>yAlff</dc:creator>
      <dc:date>2014-09-25T12:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "Error fetching event from search peer" when searching for a specific sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-Error-fetching-event-from-search-peer-quot/m-p/140375#M38771</link>
      <description>&lt;P&gt;Are any results returned at all by that search? Or do you only see that error when looking at earlier time buckets in the timeline?   And is this a distributed search environment?   &lt;/P&gt;

&lt;P&gt;It could be that you're running up against the remote_timeline_max_size_mb property in limits.conf.  This controls how much of the data returned by the search peer will actually get stored in the search's dispatch directory.    The default is 100mb, and if the peer returns more than that,  splunk will only actually store the latest 100mb worth.  For all earlier events, when attempting to look at them by clicking on a bucket in the timeline,  you'll get that message. &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:45:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-Error-fetching-event-from-search-peer-quot/m-p/140375#M38771</guid>
      <dc:creator>pbrunel_splunk</dc:creator>
      <dc:date>2020-09-28T17:45:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "Error fetching event from search peer" when searching for a specific sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-Error-fetching-event-from-search-peer-quot/m-p/140376#M38772</link>
      <description>&lt;P&gt;Yes, this seems to be the solution. Only the "results" earlier than the last 2 days showed this error.&lt;BR /&gt;
Yes, it is a distributed search environment.&lt;/P&gt;

&lt;P&gt;Thanks for your answer. In the meatime all results started looking normal.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2014 09:44:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-Error-fetching-event-from-search-peer-quot/m-p/140376#M38772</guid>
      <dc:creator>yAlff</dc:creator>
      <dc:date>2014-10-01T09:44:44Z</dc:date>
    </item>
  </channel>
</rss>

