Reporting

How can I export more than 10000 results from the Splunk UI?

the_wolverine
Champion

It looks like there is a hard cap (10000 lines) when exporting via SplunkWeb. How, then, do I export more than 10000 lines? I really need this.

Tags (2)
1 Solution

hexx
Splunk Employee
Splunk Employee

As of Splunk 4.3, you can now export an unlimited number of events from the UI. Do note, however, that exporting too many events in that manner (typically, several millions) could cause Splunkweb to misbehave and possibly to become temporarily unresponsive.

If you really need to often export large number of events, we would still recommend the use of the outputcsv command and/or to run the search from the CLI.

View solution in original post

hexx
Splunk Employee
Splunk Employee

As of Splunk 4.3, you can now export an unlimited number of events from the UI. Do note, however, that exporting too many events in that manner (typically, several millions) could cause Splunkweb to misbehave and possibly to become temporarily unresponsive.

If you really need to often export large number of events, we would still recommend the use of the outputcsv command and/or to run the search from the CLI.

hexx
Splunk Employee
Splunk Employee

@bob999 : The csv row limit for the email alert action is indeed completely unrelated to the csv export row limit in the flashtimeline which is discussed here. I believe that the limits.conf setting that you found is pertinent to your problem, although action.email.maxresults in savedsearches.conf is probably more so.

0 Karma

r999
Path Finder

Hexx, Pease can you confirm this is fixed in 4.3? i have a scheduled saved search which emails results with CSV of results as its alert action. it seems to be truncating at 10000 rows.

This one comment by you is the only mention that this has been changed in 4.3, however i am running 4.3.1 and am still having the issue!

Could this be the reason?

limits.conf
[scheduler]
max_action_results =
* The maximum number of results to load when triggering >an alert action.
* Defaults to 10000

?

0 Karma

araitz
Splunk Employee
Splunk Employee

Splunk for Excel Export will allow you to export more than 10K results:

http://apps.splunk.com/app/760/

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...