All,
I am receiving this error message in a relatgively small Splunk stack that is brand new.
3 errors occurred while the search was executing. Therefore, search results might be incomplete. Hide errors.
[someserver.domain.com] Events might not be returned in sub-second order due to search memory limits. See search.log for more information. Increase the value of the following limits.conf setting:[search]:max_rawsize_perchunk.
Is there a tuning guide for this? Any alerts or dashboards I should be looking at?
Bumped to 1gig from 100megs and problem went away. DMC says system resources are solid still. Any downside to increasing that number?