Security

Why are logs sometimes truncated during export from the Splunk Web UI?

ozansafi
New Member

After making a search on the search head, clicking on the "Export" icon on the GUI, and after waiting up to a minute for the download to start, the file I receive has a size of 32768 bytes, whereas it should have been 284050 bytes. This happens only sometimes, and for no apparent reason.

Is this a known bug? Can I do something against it?

0 Karma

effem
Communicator

There are quite a few limitations, which could block you to get the whole data.

One of 'em is simply the fact of 50000-lines-limit on csv-exports. (even if u click on "unlimited")

0 Karma

FritzWittwer_ol
Contributor

well, I am coming back to my older request, could you please provide more details about your search query.
One Thing which comes into my mind is the default 10000 records limit on the sort command.

ozansafi
New Member

I am using "Raw Events" instead of csv as the output format. Does that still apply?

0 Karma

effem
Communicator

afaik only csv

But you can check it easily via wordcount
wc -l file

0 Karma

FritzWittwer_ol
Contributor

could you please provide more details:
how many lines does your export contain, and does your search include a sort command?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...