Splunk Search

Error while search query executing

harry_123
Loves-to-Learn Lots

Any idea what this error is. I am getting the desired results with the query but it throws below error while executing

Labels (5)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @harry_123 

Your rex seems simple and straight forward however the limits.conf having match_limit setting which is by default 100K. In your case the limit is exceeding it could be platform level match_limit setting could have been reduced by admin or really your rex is having too many matches ( unless you share the event this can not be confirmed. You can test same in regex101.com). Refer - limits.conf - Splunk Documentation

Have a chat with admin about of limit and check is there local setting that's getting overriding, you can use splunk btool command to verify.

-----

An upvote would be appreciated if it helps!

0 Karma
Get Updates on the Splunk Community!

Get Operational Insights Quickly with Natural Language on the Splunk Platform

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With ...

Stay Connected: Your Guide to August Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Unleash the Power of Splunk MCP and AI, Meet Us at .Conf 2025, and Find Even More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...