Splunk Search

Changing the default value for Results Per Page option in the Search Results Window

dpatnam
Path Finder

I would like to know if there's any way to change the default value of the "Results per page" option from 10 to a different number in the search results window? I have a search that can potentially return more than 50 events/results in a table format (50 being the max value for the Results per page option). I am running this search as a saved search and scheduling it to email a pdf attachment of the results. I noticed that in the current setup I am only seeing 10 results in the pdf attachment and the rest of the results are not accessible. I would like to know how to get around this issue.

Tags (1)
0 Karma

dpatnam
Path Finder

yannk,nick - Thank you for the info.

0 Karma

yannK
Splunk Employee
Splunk Employee

A simple method is to setup it once, and it will be conserved in your coockies.

One method is to do a copy of flashtime.xml from

$SPLUNK_HOME/etc/apps/search/default/data/ui/views/flashtimeline.xml to $SPLUNK_HOME/etc/apps/search/local/data/ui/views/flashtimeline.xml

then change the line Selected to the correct value 10 10 20 20 50 True 50

sideview
SplunkTrust
SplunkTrust

unfortunately the viewstate preferences of all the individual users will override the XML's default value. So as an admin you could go and find and annihilate a bunch of viewstate stanzas sprayed across the user directories but it's hard.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...