Splunk Enterprise

What do I do with this error: The maximum number of concurrent historical searches on this instance has been reached.

rksk
Explorer

Hello Team,

Before I got this error I can't able to upload a .csv or .txt file it shows a blank screen or no data in the excel as 200 lines. 

Then I mapped the directories through settings >> data input 

it take a while to load and on search, I got this message 

"The maximum number of concurrent historical searches on this instance has been reached."

Why I got this error after 3 days of installing Splunk enterprise free edition?

 

any help is greatly appreciated 

 

thank you

rksk

 

 

Labels (1)
0 Karma
1 Solution

PaulPanther
Motivator

Okay, you should consider to reinstall the Splunk Enterprise from the scratch and try to ingest the file again via "Add data"

View solution in original post

Tags (1)
0 Karma

PaulPanther
Motivator

Do you have any license violation warnings which may prevent searching? What is the size of the csv file?

0 Karma

rksk
Explorer

I don't see any license violation warning, The csv file size is 125 kb

 

Two more messages  ..

The TCP output processor has paused the data flow. Forwarding to host_dest= inside output group default-autolb-group from host_src=training has been blocked for blocked_seconds=10. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data. Learn more.11/9/2022, 1:45:39 AM
Unable to initialize modular input "ssg_subscription_modular_input" defined in the app "splunk_secure_gateway": Introspecting scheme=ssg_subscription_modular_input: script running failed (exited with code 1)..11/9/2022, 1:45:19 AM


Unable to initialize modular input "ssg_subscription_modular_input" defined in the app "splunk_secure_gateway": Introspecting scheme=ssg_subscription_modular_input: script running failed (exited with code 1)..11/9/2022, 1:45:19 AM

 

 

0 Karma

PaulPanther
Motivator

Okay, you should consider to reinstall the Splunk Enterprise from the scratch and try to ingest the file again via "Add data"

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...