Splunk Search

Show source failing for 100/1000 events

kombi
Loves-to-Learn Lots

Event Actions > Show sources failing at 100/1000 events with the below 2 errors - 

  • [e430ac81-66f7-40b8-8c76-baa24d2813c6_wh-1f2db913c0] Streamed search execute failed because: Error in 'surrounding': Too many events (> 10000) in a single second..
  • Failed to find target event in final sorted event list. Cannot properly prune results

The result sets are not huge.. maybe 150 events. What does the above errors mean and how do we resolve this error?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...