Hello Splunkers,
These results may be truncated. This visualization is configured to display a maximum of 1000 results per series, and that limit has been reached.
I am doing asset counts for the enterprise and am using charting to demonstrate them for high level reporting purposes. I see that my numbers appears to be coming out correctly within the Search "Events" tab details but trying to get visualization is difficult because I keep running into this limit. How do I increase it? I see some older references about XML or maybe a .conf file but nothing definite.
Any suggestions?
Thanks!
Hi @lbogle
By default, chart results are truncated to 1000 as you've seen, but you can edit the limit by making a change to the charting.data.count value in simple XML. It's explained in the sub section of this documentation:
http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartDisplayissues#Search_result_truncation
You can change the value to whatever fits your needs, or you can set it to 0 to get all results as referenced here: http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartConfigurationReference#General_chart_prop...
Hope this solves your issue 🙂
Patrick
Have you opened a support case for this? We are trying to get Splunk to remove this limit and more customers behind this will help drive this.
Thanks,
Ken
Hi @lbogle
By default, chart results are truncated to 1000 as you've seen, but you can edit the limit by making a change to the charting.data.count value in simple XML. It's explained in the sub section of this documentation:
http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartDisplayissues#Search_result_truncation
You can change the value to whatever fits your needs, or you can set it to 0 to get all results as referenced here: http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartConfigurationReference#General_chart_prop...
Hope this solves your issue 🙂
Patrick
charting.data.count worked for me and charting.chart.resultTruncationLimit did not work.
For me, it works with splunk 6.3.3 and does not work with 6.3.0.
Hi @lbogle
Hmm...did you try editing the XML for both the charting.chart.resultTruncationLimit property (http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartDisplayissues#Configure_a_limit_on_a_per_... ) and charting.data.count property?
The only other helpful documentation I could find was this example:
http://docs.splunk.com/Documentation/Splunk/6.1.3/AdvancedDev/AdvChartingConfig-LayoutData#Data
I tried the XML option but it didn't seem to work either. I also tried adjusting the limits.conf as suggested above. Restarted Splunk Web between modifications as well. Any other suggestions?
Hi Patrick. Tried the web.conf fix but no go. Will try XML and get back to you.
Thanks
Hi,
I think you can change the setting in etc/system/default/limits.conf
If you look at this: http://docs.splunk.com/Documentation/Splunk/6.1.3/admin/Limitsconf it apears as though the setting you would want is "truncate_report".
Copy file to local, edit, and restart splunk.
Regards
Derek
Have you opened a case with Splunk for this? This is a hard limit which we have an enhancement request ticket open, more customers requesting this to be raised should push Splunk to fix this.