Most likely this is one of a category of problems where the URL generated by the browser to splunkweb, or by splunkweb to splunkd is too large to work. We've fixed some related issues in the 4.1.5 to 4.2 stretch, so depending upon specifics it might work in a later revision.
In short, that's a bug not a configuration.
A dumb workaround might be to use |outputcsv in your search, and then go fetch the file out of the dispatch directory on the splunk server. Obviously thats not a scalable solution, but perhaps it gets you out of a bind for the moment.
Currently, the only good path for customers to report bugs is via support. Please do so, especially with some hints as to what the set of fields looks like. I'm suspicous that it has to do partly with field name length as well as quantity. IF you can show it cuts off at exactly 500 no matter what, that is useful info!
... View more