Security

What setting can I change for a role to give them larger export capabilities?

pkeller
Contributor

I have a user whose search export results are capping at 10Mb ... But with the admin role I can export well beyond that. Anyone know the specific capability that controls this?

Thank you ... Splunk 6.6.3

valiquet
Contributor

Per Splunk official documentation, REST or SDK should be use when exporting large amount of data.
Perhaps, you could give it a shot with an email report if you don`t want to play with REST or SDK

http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Search/Exportsearchresults

0 Karma

pkeller
Contributor

A little more info ... the user is running a search that returns > 700,000 events ... and they're piping to 'reverse' ... If I remove 'reverse' from the mix, the export works. If I don't, then yes, the export writes around 10-12Mb and then redirects you to a page telling you that the search couldn't be found.

I've asked them to not use reverse for such a large dataset.

0 Karma
Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...