Splunk Search

transaction eventcount limit?

halperkins
New Member

It appears there seems to be a limit of the number of events can be in a transaction.
I am doing transactions, and it seems when the number of transactions is over 90 and I export it to CSV, it appears that the multivalued field "breaks" and the rest of the transactions spill out into other cells.
Is this an excel issue, or splunk issue?
thanks

Tags (1)
0 Karma

bmacias84
Champion

The limits.conf you can change search and search commands maximums. There are to setting for transactions maxopenevents and maxopentxn. Though I don't think you would be hitting those limits. It's possible you are hitting search result limits. Be specific with your sources and indices if your transactions span multiple systems.

Cheers

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...