Splunk Search

Problem with the number of column in a row

abhayneilam
Contributor

Hi,

I am running a query which would produce 29 column all total, but in my SPLUNK result set it is showing only upto 10 columns and rest goes to OTHER column

If it is more than 10 column in a row it will take rest of the column as a OTHER

Please let me know how to fix this issue, how to increase the number of column to be displayed in the SPLUNK Result set

Thanks in Advance

Tags (2)
0 Karma
1 Solution

abhayneilam
Contributor

yaa martin you are right, I am sorry , I was exicted that's you forgot to post the answer !! we can use limit= to limit the number of column to be displayed in the result set of SPLUNK.

Ex: If I have total of 50 columns in a result set , by default only 10 will be displayed and rest will go in OTHER field, so at that time we can give the following ..

....| chart count(Any_Field) by ID limit=50

Thanks 🙂

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could write what you did as an answer so future generations 😉 can use it.

0 Karma

abhayneilam
Contributor

It is done on my own , thanks !!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...