A user tried to export 110,000,000 events today to excel and crashed our SH twice.
How can we prevent it?
could you pls check, if crash* log exists in your search head $SPLUNK_HOME$\var\log\splunk. If it then you would possibly find an error due to which it crashed.
No crash report there...