Splunk Search

IndexScopedSearch Error

ryastrebov
Communicator

Hello Splunkers!

During search I get an error: "Error in 'IndexScopedSearch': The search failed. More than 1000000 events found at time 1361015487."

Which parameter in the limits.conf file should I increase to avoid this error?

Best regards,
Roman

0 Karma

wrangler2x
Motivator

I had this same problem in an index taking various exchange log files. After reading this comment about the 100K events indexed in one second being a limitation, I started thinking about that. I have not had this problem before upgrading to splunk 6.1.5 (I was on 4.3.1 before). I looked at their timestamps and realized that these logs are granular only to the second. So I go in touch with the admin on that system, and suggested moving to advance logging, and turning-on millisecond timestamps. I had to re-do my props.conf for the new timestamp but that was trivial, and I am not experiencing this error any more when searching. When you make this change, you switch from monitoring where the log is and the name:

W3SVC1\u_ex*.log to AdvancedLogs\DEFAULT WEB SITE\Exchange_AdvLog_H*.log

I put this in my props.conf for the new format:

detect_trailing_nulls=auto
pulldown_type = true
SHOULD_LINEMERGE = false
CHECK_FOR_HEADER = false
TIME_FORMAT = %Y-%m-%d %H:%M:%S.%3N
TZ = GMT
0 Karma

jalfrey
Communicator

Splunk returns searches in sub second order. You can not have more the 100K events indexed in one second. It is not tunable. Sorry.

0 Karma

ryastrebov
Communicator

Maybe this is hard limitation of Splunk?...

0 Karma

a212830
Champion

Curious as well - having the same issue.

0 Karma

a212830
Champion

Curious as well - running into the same situation.

0 Karma

ryastrebov
Communicator

The problem is still not resolved...

0 Karma

ryastrebov
Communicator

Thank you!
I found this answer earlier. But I do not quite understand what kind of setting it:
"parameter tunable based on memory available"

Increase value of parameter "max_mem_usage_mb" doesn't affect the Error...

0 Karma

smolcj
Builder

i think both are same . please check out [here][1]

 [1]: http://splunk-base.splunk.com/answers/3397/indexscopedsearch-error-details
0 Karma

ryastrebov
Communicator

Not have any ideas?

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...