Spluk is restricting to 500 records when we try to post the records to AWS database using webhook post.
We are getting below error messages, can some pls help.
SavedSplunker - Reached maximum number of per-result alerts for savedsearch_id
max_alerts=500, fired_alerts=500
See the appropriate settings for your version of splunk in limits.conf
http://docs.splunk.com/Documentation/Splunk/7.1.2/Admin/Limitsconf
In particular the options in [scheduler] such as this one:
max_per_result_alerts = <int>
* Maximum number of alerts to trigger for each saved search instance (or
real-time results preview for RT alerts)
* Only applies in non-digest mode alerting. Use 0 to disable this limit
* Default: 500