How do we index a data file which is an aggregated data for a given day. The data does not contain timestamp.
Splunk gives an error while searching- saying that "Error in IndexScopedSearch: The search failed. More than XXX events found at time t"
I've looked at these forums and found the following link, which tells me its a limitation on Splunk.
- Max number events at the same timestamp
- Tuning Search with more than 250K events at one timestamp
- Disable timestamp processor
Consider the following use-case.
Imagine, you are looking at a stock price data on a day-scale for 6 months. The data file in this case, may contain ticker price for a given day. If the data points are more than 100K, since there is no timestamp, Splunk given the error during search time.
Has anyone figured how to workaround this?