Reporting

How can I export more than 10000 results from the Splunk UI?

the_wolverine
Champion

It looks like there is a hard cap (10000 lines) when exporting via SplunkWeb. How, then, do I export more than 10000 lines? I really need this.

Tags (2)
1 Solution

hexx
Splunk Employee
Splunk Employee

As of Splunk 4.3, you can now export an unlimited number of events from the UI. Do note, however, that exporting too many events in that manner (typically, several millions) could cause Splunkweb to misbehave and possibly to become temporarily unresponsive.

If you really need to often export large number of events, we would still recommend the use of the outputcsv command and/or to run the search from the CLI.

View solution in original post

hexx
Splunk Employee
Splunk Employee

As of Splunk 4.3, you can now export an unlimited number of events from the UI. Do note, however, that exporting too many events in that manner (typically, several millions) could cause Splunkweb to misbehave and possibly to become temporarily unresponsive.

If you really need to often export large number of events, we would still recommend the use of the outputcsv command and/or to run the search from the CLI.

hexx
Splunk Employee
Splunk Employee

@bob999 : The csv row limit for the email alert action is indeed completely unrelated to the csv export row limit in the flashtimeline which is discussed here. I believe that the limits.conf setting that you found is pertinent to your problem, although action.email.maxresults in savedsearches.conf is probably more so.

0 Karma

r999
Path Finder

Hexx, Pease can you confirm this is fixed in 4.3? i have a scheduled saved search which emails results with CSV of results as its alert action. it seems to be truncating at 10000 rows.

This one comment by you is the only mention that this has been changed in 4.3, however i am running 4.3.1 and am still having the issue!

Could this be the reason?

limits.conf
[scheduler]
max_action_results =
* The maximum number of results to load when triggering >an alert action.
* Defaults to 10000

?

0 Karma

araitz
Splunk Employee
Splunk Employee

Splunk for Excel Export will allow you to export more than 10K results:

http://apps.splunk.com/app/760/

Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...