I'm trying to run a metadata search on type=hosts and am being capped in the UI to 10,000 results. I've already increased the limits.conf setting per the following answers post:
http://answers.splunk.com/questions/3197/metadata-typesources-maxes-out-at-10000-limits-conf-setting
How can I get Splunk to return a complete listing?
What version of Splunk are you running? Please provide a diag file with your answer.
The setting described works in 4.1.x, but not in 4.0.x.
Update:
Seems this setting doesn't work as described in 4.1.3. I have a 4.1.3 search head, and five 4.1.3 indexers. All of them have the default setting in limits.conf, which is 100,000 (not 10,000):
[metadata]
# the most metadata results to fetch from each indexer.
maxcount = 100000
However, running
| metadata type=sources
limits me to 10,000 results, and
| metadata type=sources | stats count
gives me 10,000.
You can keep your diag.
limits.conf
isn't propagated from the search head, so you should set on all servers.
Hmm, so I had updated the limits.conf setting on the search head. Does this change need to occur at the indexers themselves?
What version of Splunk are you running? Please provide a diag file with your answer.
The setting described works in 4.1.x, but not in 4.0.x.
Update:
Seems this setting doesn't work as described in 4.1.3. I have a 4.1.3 search head, and five 4.1.3 indexers. All of them have the default setting in limits.conf, which is 100,000 (not 10,000):
[metadata]
# the most metadata results to fetch from each indexer.
maxcount = 100000
However, running
| metadata type=sources
limits me to 10,000 results, and
| metadata type=sources | stats count
gives me 10,000.
You can keep your diag.
All of your diags are unreadable. Please resubmit all of them. Thank you.
I'm using version 4.1.2 and it isn't working. There was a diag submitted with one of my recent cases. Please look at all my cases and let me know if you don't see it. kthxbai.