Splunk Search

Error while search query executing

harry_123
Loves-to-Learn Lots

Any idea what this error is. I am getting the desired results with the query but it throws below error while executing

Labels (5)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @harry_123 

Your rex seems simple and straight forward however the limits.conf having match_limit setting which is by default 100K. In your case the limit is exceeding it could be platform level match_limit setting could have been reduced by admin or really your rex is having too many matches ( unless you share the event this can not be confirmed. You can test same in regex101.com). Refer - limits.conf - Splunk Documentation

Have a chat with admin about of limit and check is there local setting that's getting overriding, you can use splunk btool command to verify.

-----

An upvote would be appreciated if it helps!

0 Karma
Get Updates on the Splunk Community!

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...