Splunk Search
Highlighted

How can I tune the Splunk search process to handle more than 250000 events at one timestamp?

Path Finder

I have a data source where all events get logged in hour intervals. There could be several hundred thousand events per interval.

When trying to search for these events I get the following error: Error in 'IndexScopedSearch': The search failed. More than 250000 events found at time 1271749500.

Is there a way to tune the search process not to fail on this search?

Tags (3)
0 Karma
Highlighted

Re: How can I tune the Splunk search process to handle more than 250000 events at one timestamp?

Splunk Employee
Splunk Employee
Highlighted

Re: How can I tune the Splunk search process to handle more than 250000 events at one timestamp?

Path Finder

Unfortunately I am still running into this limitation. I have tried to add some information to from the event's _raw field to the Sourcetype, in order to increase the uniqueness of the host/source/sourcetype combination. My searches are still failing though.

0 Karma
Highlighted

Re: How can I tune the Splunk search process to handle more than 250000 events at one timestamp?

Path Finder

We resolved this issue by moving away from timestamp recognition for this data source and logging TIME_FORMAT=CURRENT.

0 Karma