Splunk Search

The search failed. More than 125000 events found at time

ddholstadz
Explorer

I get this error which I suspect is from reading in a file whith no timestamps in it?

Error in 'IndexScopedSearch': The search failed. More than 125000 events found at time 1293916026.

1) Is there an easy way to see which file caused the error 2) Is there a was to force Splunk to spread the file across multiple timestamps?

Tags (1)
1 Solution

sideview
SplunkTrust
SplunkTrust
0 Karma

sideview
SplunkTrust
SplunkTrust
0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!