Splunk Search

Problem with the number of column in a row

abhayneilam
Contributor

Hi,

I am running a query which would produce 29 column all total, but in my SPLUNK result set it is showing only upto 10 columns and rest goes to OTHER column

If it is more than 10 column in a row it will take rest of the column as a OTHER

Please let me know how to fix this issue, how to increase the number of column to be displayed in the SPLUNK Result set

Thanks in Advance

Tags (2)
0 Karma
1 Solution

abhayneilam
Contributor

yaa martin you are right, I am sorry , I was exicted that's you forgot to post the answer !! we can use limit= to limit the number of column to be displayed in the result set of SPLUNK.

Ex: If I have total of 50 columns in a result set , by default only 10 will be displayed and rest will go in OTHER field, so at that time we can give the following ..

....| chart count(Any_Field) by ID limit=50

Thanks 🙂

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could write what you did as an answer so future generations 😉 can use it.

0 Karma

abhayneilam
Contributor

It is done on my own , thanks !!

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...