I tried to test map command on Splunk 7.1.3 with following search:
index=_internal earliest=-60m | map maxsearches=1 search="search index=_internal earliest=-6m latest=-1m | head 1"
Theoretically, this search should only return one event from index=_internal.
However, lots of events from main index return
Is this a bug?
This is a known issue SPL-167869 and SPL-169704 which will be fixed on 7.3.
Workaround is also available:
add following stanza in ../etc/system/local/limits.conf on SH and restart should fix this issue:
[search]
phased_execution_mode = auto
After workaround applied: