Hello Splunk enjoyers! I loaded some data(10 000 000), with fields: updated_time, info, user and discription, to my new index "data_tmp". So when i search, i got a problem Error in 'IndexScopedSearch': The search failed. More than 1000000 events found at time 1677582000.
My search: So i tried to extract by updated_time like: index = data_tmp eval _time = strftime(updated,"%Y-%m-%d %H:%M:%S.%3N") | convert ctime(_time) | fieldformat _time = strftime(updated,"%Y-%m-%d %H:%M:%S.%3N") but nothing works. Can somebody help me with that? thank you!
... View more