<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error in 'IndexScopedSearch': The search failed. More than 125000 events found at time 1283184202 in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Error-in-IndexScopedSearch-The-search-failed-More-than-125000/m-p/40777#M9421</link>
    <description>&lt;P&gt;I can't seem to comment on Answers in Internet Explorer 8 (32bit) or FireFox 3.6.8.&lt;/P&gt;

&lt;P&gt;I have read that answer before posting, but it does not seem to relate.  If it does relate, I am missing the point.  I seriously doubt that we have any single host producing 100,000 messages per second.&lt;/P&gt;

&lt;P&gt;I have quite a number of successful searches prior to receiving this error.  It seems like I hit some limit on searches and this error appears.  The search time frame is the last 24 hours, and I do not see any recent events that would number more than a dozen or so over the last 15 minutes after first seeing the error.&lt;/P&gt;

&lt;P&gt;It might be an internal error, but is there a workaround such as clearing the IndexScopedSearch index? Since I don't know if that index is temporary or not, I don't know if that is a good or bad thing to do.  If it is okay to clear out the index, I don't know how to do that.&lt;/P&gt;

&lt;P&gt;Thank you
Randy&lt;/P&gt;</description>
    <pubDate>Tue, 31 Aug 2010 22:53:14 GMT</pubDate>
    <dc:creator>RNB</dc:creator>
    <dc:date>2010-08-31T22:53:14Z</dc:date>
    <item>
      <title>Error in 'IndexScopedSearch': The search failed. More than 125000 events found at time 1283184202</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-IndexScopedSearch-The-search-failed-More-than-125000/m-p/40775#M9419</link>
      <description>&lt;P&gt;I started seeing this error yesterday, and the Splunk&amp;gt;answers responses so far don't seem to fit a pattern I am seeing.  I seem to get this after I do a lot of searches within a specific time frame, such as last 24 hours.  It seems like the "IndexScopedSearch" is retaining/accumulating timestamped data.  Is this Index used only to store search results?&lt;/P&gt;

&lt;P&gt;I have attempted to see what events were logged at time 1283183159, but I get zero results with searches such as time=1283183159, _time=1283183159 or timestamp=1283183159.  How do I find events at the specified time?&lt;/P&gt;

&lt;P&gt;Thank you
Randy&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2010 22:09:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-IndexScopedSearch-The-search-failed-More-than-125000/m-p/40775#M9419</guid>
      <dc:creator>RNB</dc:creator>
      <dc:date>2010-08-31T22:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: Error in 'IndexScopedSearch': The search failed. More than 125000 events found at time 1283184202</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-IndexScopedSearch-The-search-failed-More-than-125000/m-p/40776#M9420</link>
      <description>&lt;P&gt;This &lt;A href="http://answers.splunk.com/questions/303/whats-max-events-i-can-have-timestamped-with-a-particular-second-millisecond" rel="nofollow"&gt;answer&lt;/A&gt; explains what you are seeing I think. It is possible that the data is getting timestamped incorrectly by Splunk, but we'd need more information.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2010 22:20:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-IndexScopedSearch-The-search-failed-More-than-125000/m-p/40776#M9420</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-08-31T22:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: Error in 'IndexScopedSearch': The search failed. More than 125000 events found at time 1283184202</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-IndexScopedSearch-The-search-failed-More-than-125000/m-p/40777#M9421</link>
      <description>&lt;P&gt;I can't seem to comment on Answers in Internet Explorer 8 (32bit) or FireFox 3.6.8.&lt;/P&gt;

&lt;P&gt;I have read that answer before posting, but it does not seem to relate.  If it does relate, I am missing the point.  I seriously doubt that we have any single host producing 100,000 messages per second.&lt;/P&gt;

&lt;P&gt;I have quite a number of successful searches prior to receiving this error.  It seems like I hit some limit on searches and this error appears.  The search time frame is the last 24 hours, and I do not see any recent events that would number more than a dozen or so over the last 15 minutes after first seeing the error.&lt;/P&gt;

&lt;P&gt;It might be an internal error, but is there a workaround such as clearing the IndexScopedSearch index? Since I don't know if that index is temporary or not, I don't know if that is a good or bad thing to do.  If it is okay to clear out the index, I don't know how to do that.&lt;/P&gt;

&lt;P&gt;Thank you
Randy&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2010 22:53:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-IndexScopedSearch-The-search-failed-More-than-125000/m-p/40777#M9421</guid>
      <dc:creator>RNB</dc:creator>
      <dc:date>2010-08-31T22:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: Error in 'IndexScopedSearch': The search failed. More than 125000 events found at time 1283184202</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-IndexScopedSearch-The-search-failed-More-than-125000/m-p/40778#M9422</link>
      <description>&lt;P&gt;I got this "Error in 'IndexScopedSearch': The search failed. More than 125000 events found at time 1287172432." and an error notice that I went over my indexing volume license. So, I am trying to figure out what happened and cannot find the source that generated all these 'events'.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2010 04:12:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-IndexScopedSearch-The-search-failed-More-than-125000/m-p/40778#M9422</guid>
      <dc:creator>chicodeme</dc:creator>
      <dc:date>2010-10-19T04:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: Error in 'IndexScopedSearch': The search failed. More than 125000 events found at time 1283184202</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-IndexScopedSearch-The-search-failed-More-than-125000/m-p/40779#M9423</link>
      <description>&lt;P&gt;BTW, you need a higher score before you can add a comment; it's not your browser.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2011 22:54:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-IndexScopedSearch-The-search-failed-More-than-125000/m-p/40779#M9423</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2011-01-06T22:54:42Z</dc:date>
    </item>
  </channel>
</rss>

