Splunk Search

How can I tune the Splunk search process to handle more than 250000 events at one timestamp?

stephanbuys
Path Finder

I have a data source where all events get logged in hour intervals. There could be several hundred thousand events per interval.

When trying to search for these events I get the following error: Error in 'IndexScopedSearch': The search failed. More than 250000 events found at time 1271749500.

Is there a way to tune the search process not to fail on this search?

Tags (3)
0 Karma
1 Solution

stephanbuys
Path Finder

We resolved this issue by moving away from timestamp recognition for this data source and logging TIME_FORMAT=CURRENT.

0 Karma

stephanbuys
Path Finder

Unfortunately I am still running into this limitation. I have tried to add some information to from the event's _raw field to the Sourcetype, in order to increase the uniqueness of the host/source/sourcetype combination. My searches are still failing though.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...