Reporting

How can I export more than 10000 results from the Splunk UI?

the_wolverine
Champion

It looks like there is a hard cap (10000 lines) when exporting via SplunkWeb. How, then, do I export more than 10000 lines? I really need this.

Tags (2)
1 Solution

hexx
Splunk Employee
Splunk Employee

As of Splunk 4.3, you can now export an unlimited number of events from the UI. Do note, however, that exporting too many events in that manner (typically, several millions) could cause Splunkweb to misbehave and possibly to become temporarily unresponsive.

If you really need to often export large number of events, we would still recommend the use of the outputcsv command and/or to run the search from the CLI.

View solution in original post

hexx
Splunk Employee
Splunk Employee

As of Splunk 4.3, you can now export an unlimited number of events from the UI. Do note, however, that exporting too many events in that manner (typically, several millions) could cause Splunkweb to misbehave and possibly to become temporarily unresponsive.

If you really need to often export large number of events, we would still recommend the use of the outputcsv command and/or to run the search from the CLI.

hexx
Splunk Employee
Splunk Employee

@bob999 : The csv row limit for the email alert action is indeed completely unrelated to the csv export row limit in the flashtimeline which is discussed here. I believe that the limits.conf setting that you found is pertinent to your problem, although action.email.maxresults in savedsearches.conf is probably more so.

0 Karma

r999
Path Finder

Hexx, Pease can you confirm this is fixed in 4.3? i have a scheduled saved search which emails results with CSV of results as its alert action. it seems to be truncating at 10000 rows.

This one comment by you is the only mention that this has been changed in 4.3, however i am running 4.3.1 and am still having the issue!

Could this be the reason?

limits.conf
[scheduler]
max_action_results =
* The maximum number of results to load when triggering >an alert action.
* Defaults to 10000

?

0 Karma

araitz
Splunk Employee
Splunk Employee

Splunk for Excel Export will allow you to export more than 10K results:

http://apps.splunk.com/app/760/

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...