Hi Team,
We are receiving warn message as below on search head clusters.
"The limit has been reached for log messages in info.csv. 18 messages have not been written to info.csv. Refer to search.log for these messages or limits.conf to configure this limit."
What is relevance of info.csv and how this limit breach affect Splunk search performance and search results.
Thanks,
Mani
Hi @manikandankasi,
Messages logged to the info.csv file are available to REST API clients and Splunk Web. You can find info about info.csv here (https://docs.splunk.com/Documentation/Splunk/8.1.2/Admin/Limitsconf#.5Bsearch_info.5D )
Default value for max_infocsv_messages is 20 , you can increase this value to 50 or 100 for your case on indexers.
[search_info]
max_infocsv_messages = 100