|
I seem to be stuck with the 100 result limit for a subsearch. I've changed maxout= to 10000 in limits.conf (and restarted Splunk), but still no luck. Any ideas on what else to try? We are on 4.1.2, btw. Thanks, Mike |
|
Pretty much seems like bug to me, either in product or documentation. You are actually supposed to change:
or whatever, as the default subsearch Update: Okay, it appears that there some missing documentation, both in the online docs and (oddly) in the in-product docs for the Thanks for the info. I missed the description for format/maxresults when I was scanning through the limits.conf file.
(28 May '10, 17:11)
msallman
Thanks. Piping through format in the subsearch works.
(04 Jun '10, 13:16)
msallman
Thanks. Piping through format in the subsearch works.
(04 Jun '10, 13:18)
msallman
|

updated answer with a solution below