Splunk Search

The search you ran returned a number of fields that exceeded the current indexed field extraction limit='200'

jbanAtSplunk
Communicator

The search you ran returned a number of fields that exceeded the current indexed field extraction limit='200'
To ensure that all fields are extracted for search, set limits.conf: [kv] / indexed_kv_limit to a number that is higher than the number of fields contained in the files that you index.

Hi,

I am getting above error while on the left side I have only 35-10 fields extracted during search time.
Log is ingested with Splunk HEC using Splunk_TA_nix with linux_secure stanza.

How can I detect what is causing above error as didn't find anything that will create indexed fields, etc...and I didn't see fields on the left created.

How to troubleshoot this?

With search like this, I got 11 fields
| walklex index="<index_name>" type=field
| search NOT field=" *"
| stats list(distinct_values) by field


Labels (2)
0 Karma
Get Updates on the Splunk Community!

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...