Splunk Search

How to increase truncation limit to display all results in a chart?

lbogle
Contributor

Hello Splunkers,

These results may be truncated. This visualization is configured to display a maximum of 1000 results per series, and that limit has been reached.

I am doing asset counts for the enterprise and am using charting to demonstrate them for high level reporting purposes. I see that my numbers appears to be coming out correctly within the Search "Events" tab details but trying to get visualization is difficult because I keep running into this limit. How do I increase it? I see some older references about XML or maybe a .conf file but nothing definite.

Any suggestions?

Thanks!

Tags (3)
1 Solution

ppablo
Retired

Hi @lbogle

By default, chart results are truncated to 1000 as you've seen, but you can edit the limit by making a change to the charting.data.count value in simple XML. It's explained in the sub section of this documentation:
http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartDisplayissues#Search_result_truncation

You can change the value to whatever fits your needs, or you can set it to 0 to get all results as referenced here: http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartConfigurationReference#General_chart_prop...

Hope this solves your issue 🙂

Patrick

View solution in original post

kbecker
Communicator

Have you opened a support case for this? We are trying to get Splunk to remove this limit and more customers behind this will help drive this.

Thanks,
Ken

0 Karma

ppablo
Retired

Hi @lbogle

By default, chart results are truncated to 1000 as you've seen, but you can edit the limit by making a change to the charting.data.count value in simple XML. It's explained in the sub section of this documentation:
http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartDisplayissues#Search_result_truncation

You can change the value to whatever fits your needs, or you can set it to 0 to get all results as referenced here: http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartConfigurationReference#General_chart_prop...

Hope this solves your issue 🙂

Patrick

mark_chuman
Path Finder

charting.data.count worked for me and charting.chart.resultTruncationLimit did not work.

0 Karma

akazarov
Path Finder

For me, it works with splunk 6.3.3 and does not work with 6.3.0.

0 Karma

ppablo
Retired

Hi @lbogle

Hmm...did you try editing the XML for both the charting.chart.resultTruncationLimit property (http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartDisplayissues#Configure_a_limit_on_a_per_... ) and charting.data.count property?

The only other helpful documentation I could find was this example:
http://docs.splunk.com/Documentation/Splunk/6.1.3/AdvancedDev/AdvChartingConfig-LayoutData#Data

0 Karma

lbogle
Contributor

I tried the XML option but it didn't seem to work either. I also tried adjusting the limits.conf as suggested above. Restarted Splunk Web between modifications as well. Any other suggestions?

0 Karma

lbogle
Contributor

Hi Patrick. Tried the web.conf fix but no go. Will try XML and get back to you.
Thanks

0 Karma

DerekKing
Path Finder

Hi,

I think you can change the setting in etc/system/default/limits.conf

If you look at this: http://docs.splunk.com/Documentation/Splunk/6.1.3/admin/Limitsconf it apears as though the setting you would want is "truncate_report".

Copy file to local, edit, and restart splunk.

Regards
Derek

0 Karma

kbecker
Communicator

Have you opened a case with Splunk for this? This is a hard limit which we have an enhancement request ticket open, more customers requesting this to be raised should push Splunk to fix this.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...