报错信息
Events may not be returned in sub-second order due to search memory limits configured in limits.conf :max_rawsize_perchunk. See search.log for more information.
处理办法
1. 打开Splunk安装目录
2. 根据「etc\system\default」路径信息,找到「limits.conf」文件。
3. 修改「max_rawsize_perchunk」
# Maximum raw size of results for each call to search (in dispatch).
# 0 = no limit, not affected by chunk_multiplier.
max_rawsize_perchunk = 800000000
4. 重启Splunk
net stop splunkd
net start splunkd