Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

Search generated too much data...

$
0
0

Has anyone run into this message?

"Search generated too much data for the current display configuration, results have been truncated"

The search is for collecting and grouping latency times (spent).

source="/opt/splunk/var/log/splunk/web_access.log"
| eval dum=case(spent==0, spent) | eval 0-99(ms)=case(spent>=0 AND spent<=99, spent) | eval 100-199(ms)=case(spent>=100 AND spent<=199, spent) | eval 200-299(ms)=case(spent>=200 AND spent<=299, spent) | eval 300-399(ms)=case(spent>=300 AND spent<=399, spent) | eval 400-499(ms)=case(spent>=400 AND spent<=499, spent) | eval over500(ms)=case(spent>=500, spent) | table spent 0-99(ms) 100-199(ms) 200-299(ms) 300-399(ms) 400-499(ms) over500(ms)


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>