we are getting the below errors from splunkd.log. the issue is we weren't able to search the logs from splunk console:
have tried editing TRUNCATE & DATETIME_CONFIG, this didn't help. can any one please help
07-26-2018 15:41:55.605 +0200 WARN AggregatorMiningProcessor - Breaking event because limit of 256 has been exceeded - data_source=
props.cong MAX_EVENTS
see this answer:
https://answers.splunk.com/answers/141721/error-in-splunkd-log-breaking-event-because-limit-of-256-h...
make sure to have the props.conf on your first full splunk instance Heavy Forwarder OR Indexer
hope it helps