Hi All,
getting following error in splunk:
"Events may not be returned in sub-second order due to search memory limits . See search.log for more information. settings: [search]:max_rawsize_perchu...
See more...
Hi All,
getting following error in splunk:
"Events may not be returned in sub-second order due to search memory limits . See search.log for more information. settings: [search]:max_rawsize_perchunk"
when i am searching for paticular time range like : 4 to 8 i am getting this error. but if i search for last 15 mins or 24 hours or last 7 days i am not getting the error. I understood : that between 4 to 8 timerange there where lot events coming for one second. 1. below are my props configured and sample logs: 20221012453012 20220812453012 20220912453012 20220612453012 H1S98765~~PR~;R ESC~AB~Thu Oct 12 12:34:56 IST 2022~B~1.22~2.22~3456.98~GF~4356BV H1S98765~~PR~;Z ESC~AB~Thu Oct 12 12:34:56 IST 2022~B~1.22~2.22~3456.98~GF~4356BV H1S98765~~PR~;M ESC~AB~Thu Oct 12 12:34:56 IST 2022~B~1.22~2.22~3456.98~GF~4356BV H1S98765~~PR~;T ESC~AB~Thu Oct 12 12:34:56 IST 2022~B~1.22~2.22~3456.98~GF~4356BV [logs:health:app] truncate=10000 time_prefix=(?:[^~]+~)~(?:[^~]+~){3} time_format=%a %b %d %H: %M: %S %Z disable=false max_timestamp_lookahead=75 charset=UFT_8 no_binary_check=true datetime_config=CURRENT should_linenerge=false line_breaker=([\r\n]+)\w{8}~~ annotate_punct=false
2. below are my props configured and sample logs: [10/07/22 12:55:40"7451 IST] 89786545 medapplog 9[10/07/22 12:55:40"7451 IST-897654] [app=med, sucees=0, failed=10, validpoints=100] the events are assocuiated with the med application user=app client=med [08/07/22 12:55:40"7451 IST] 89786545 medapplog 9[10/07/22 12:55:40"7451 IST-897654] [app=med, sucees=0, failed=10, validpoints=100] the events are assocuiated with the med application user=app client=med [10/12/22 12:55:40"7451 IST] 89786545 medapplog 9[10/07/22 12:55:40"7451 IST-897654] [app=med, sucees=0, failed=10, validpoints=100] the events are assocuiated with the med application user=app client=med [logs:med:app] time_prefix=^\[ time_format=%m %d %y %H: %M: %S: %3Q %Z max_timestamp_lookahead=30 should_linenerge=false line_breaker=([\r\n]+)\[\d{1,2}\/\d{1,2}\/\d{2}\s\d{1,2}:\d{2}:\d{2}:\d{3}\s\D{3}\] truncate=99999
please let me know how to avoid this error coming when i search.