Splunk Search

Error in 'IndexScopedSearch': The search failed

msmith12
Engager
We're trying to run a search but are getting these errors while doing so:

3 errors occurred while the search was executing. Therefore, search results might be incomplete.
  • [indexer1] Error in 'IndexScopedSearch': The search failed. More than 1000000 events found at time 1624492800.
  • [indexer2] Error in 'IndexScopedSearch': The search failed. More than 1000000 events found at time 1624510800.
  • [indexer3] Events might not be returned in sub-second order due to search memory limits. See search.log for more information. Increase the value of the following limits.conf setting:[search]:max_rawsize_perchunk.

We've increased our max_rawsize_perchunk limit on the indexers but are still seeing these errors. We're running Splunk Enterprise 8.0.0

How would we make this error go away? TIA!

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...