I had this same problem in an index taking various exchange log files. After reading this comment about the 100K events indexed in one second being a limitation, I started thinking about that. I have not had this problem before upgrading to splunk 6.1.5 (I was on 4.3.1 before). I looked at their timestamps and realized that these logs are granular only to the second. So I go in touch with the admin on that system, and suggested moving to advance logging, and turning-on millisecond timestamps. I had to re-do my props.conf for the new timestamp but that was trivial, and I am not experiencing this error any more when searching. When you make this change, you switch from monitoring where the log is and the name:
W3SVC1\u_ex*.log to AdvancedLogs\DEFAULT WEB SITE\Exchange_AdvLog_H*.log
I put this in my props.conf for the new format:
detect_trailing_nulls=auto
pulldown_type = true
SHOULD_LINEMERGE = false
CHECK_FOR_HEADER = false
TIME_FORMAT = %Y-%m-%d %H:%M:%S.%3N
TZ = GMT
... View more