Splunk Search

metadata search is restricted to 10000 results

the_wolverine
Champion

I'm trying to run a metadata search on type=hosts and am being capped in the UI to 10,000 results. I've already increased the limits.conf setting per the following answers post:

http://answers.splunk.com/questions/3197/metadata-typesources-maxes-out-at-10000-limits-conf-setting

How can I get Splunk to return a complete listing?

1 Solution

gkanapathy
Splunk Employee
Splunk Employee

What version of Splunk are you running? Please provide a diag file with your answer.

The setting described works in 4.1.x, but not in 4.0.x.


Update:

Seems this setting doesn't work as described in 4.1.3. I have a 4.1.3 search head, and five 4.1.3 indexers. All of them have the default setting in limits.conf, which is 100,000 (not 10,000):

[metadata]
# the most metadata results to fetch from each indexer.
maxcount = 100000

However, running

| metadata type=sources

limits me to 10,000 results, and

| metadata type=sources | stats count

gives me 10,000.

You can keep your diag.

View solution in original post

Stephen_Sorkin
Splunk Employee
Splunk Employee

limits.conf isn't propagated from the search head, so you should set on all servers.

the_wolverine
Champion

Hmm, so I had updated the limits.conf setting on the search head. Does this change need to occur at the indexers themselves?

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

What version of Splunk are you running? Please provide a diag file with your answer.

The setting described works in 4.1.x, but not in 4.0.x.


Update:

Seems this setting doesn't work as described in 4.1.3. I have a 4.1.3 search head, and five 4.1.3 indexers. All of them have the default setting in limits.conf, which is 100,000 (not 10,000):

[metadata]
# the most metadata results to fetch from each indexer.
maxcount = 100000

However, running

| metadata type=sources

limits me to 10,000 results, and

| metadata type=sources | stats count

gives me 10,000.

You can keep your diag.

gkanapathy
Splunk Employee
Splunk Employee

All of your diags are unreadable. Please resubmit all of them. Thank you.

0 Karma

the_wolverine
Champion

I'm using version 4.1.2 and it isn't working. There was a diag submitted with one of my recent cases. Please look at all my cases and let me know if you don't see it. kthxbai.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...