Splunk Search

How can I tune the Splunk search process to handle more than 250000 events at one timestamp?

stephanbuys
Path Finder

I have a data source where all events get logged in hour intervals. There could be several hundred thousand events per interval.

When trying to search for these events I get the following error: Error in 'IndexScopedSearch': The search failed. More than 250000 events found at time 1271749500.

Is there a way to tune the search process not to fail on this search?

Tags (3)
0 Karma
1 Solution

stephanbuys
Path Finder

We resolved this issue by moving away from timestamp recognition for this data source and logging TIME_FORMAT=CURRENT.

0 Karma

stephanbuys
Path Finder

Unfortunately I am still running into this limitation. I have tried to add some information to from the event's _raw field to the Sourcetype, in order to increase the uniqueness of the host/source/sourcetype combination. My searches are still failing though.

0 Karma
Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...