今天客户发现search 大量数据的时候报错:
报错:Events might not be returned in sub-second order due to search memory limits, increase the value of the following limits.conf setting :[search]: max_rawsize_perchunk.
查询官方文档:limits.conf - Splunk Documentation
后来在splunk 的index server 上面: /opt/splunk/etc/system/local 下面编辑文件: limits.conf
[root@abc local]# cat limits.conf
[search]
max_rawsize_perchunk = 2000000000
然后在restart splunk 就可以了,这样就没有上面的报错。解决问题。