Splunk Search

Fix Error: IndexScopedSearch?

splunk_enjoyer
Explorer

Hello Splunk enjoyers!
I loaded some data(10 000 000), with fields: updated_time, info, user and discription,  to my new index "data_tmp".

So when i search, i got a problem  Error in 'IndexScopedSearch': The search failed. More than 1000000 events found at time 1677582000.

My search:

So i tried to extract by updated_time like:
index = data_tmp
 eval _time = strftime(updated,"%Y-%m-%d %H:%M:%S.%3N")
| convert ctime(_time)
| fieldformat _time = strftime(updated,"%Y-%m-%d %H:%M:%S.%3N")

but nothing works.
Can somebody help me with that?
thank you!




Labels (3)
Tags (2)
0 Karma

abedcx
Explorer

did you fix it ? 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

This is a fundamental problem with the data badly ingested into Splunk.

Splunk returns results in reverse chronological order so it needs to be able to sort the results properly based on the _original_ value of the _time field. (afterwards the _time field can be rewritten during the search pipeline and it won't affect the result order). If you have several hundred thousand events indexed at the same point in time, Splunk cannot sort them due to memory constraints.

It's not a problem with the search as such but it's a problem with the data - fix your data onboarding.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...