All Apps and Add-ons

Too many results returned

araitz
Splunk Employee
Splunk Employee

dmlee asks:

Hi,

thanks for your great App, I do a test using ver 1.3.1 and find a problem, for example I search 10,000 rows : source="/opt/apache/log/access_combined.log"| head 10000 | table action, bytes, clientip

and I use ExportExcel module to export above result set, but I got 13,740 rows in excel ! I tried to search and export 1,000 rows , I will get correct results.

I don't know why.

Regards,

Owen

1 Solution

araitz
Splunk Employee
Splunk Employee

I am currently working on version 2.0, the road map for which is listed here: http://splunk-base.splunk.com/apps/29336/splunk-for-excel-export. I have reproduced a few cases where too many results were returned, or where multiline exports had partial _raw fields. I am working on fixing these issues for 2.0 as well.

EDIT: Version 2.0 was released on May 13th and includes several performance and stability improvements.

View solution in original post

araitz
Splunk Employee
Splunk Employee

I am currently working on version 2.0, the road map for which is listed here: http://splunk-base.splunk.com/apps/29336/splunk-for-excel-export. I have reproduced a few cases where too many results were returned, or where multiline exports had partial _raw fields. I am working on fixing these issues for 2.0 as well.

EDIT: Version 2.0 was released on May 13th and includes several performance and stability improvements.

Takajian
Builder

Addition to previous my comment, I used browser Google Chrome 17, Firefox 9, IE 9. Splunk OS is 4.3.1. I see this issue with any type of data. The platform is linux. Do you have any idea to solve the issue?

0 Karma

Takajian
Builder

In my case, I used chart and stats command. The result was 10 rows, but I exported over 100 rows with excel. The search command is like "sourcetype=xxxx | chart count by yyyy" or "sourcetype=xxxx | stats count by yyyy". I assume this issue can be reproduce on other splunk instances. If you need more info to reproduce the issue in your environment, please let me know.

0 Karma

araitz
Splunk Employee
Splunk Employee

I am working on reproducing the issues. Any additional information that you can provide with regard to the type of data and your browser and Splunk OS version would be awesome.

0 Karma

Takajian
Builder

I faced the same issue. The ExportExcel module exports incorrect search results. I hope this issue will be fixed soon.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...