All Apps and Add-ons

Too many results returned

araitz
Splunk Employee
Splunk Employee

dmlee asks:

Hi,

thanks for your great App, I do a test using ver 1.3.1 and find a problem, for example I search 10,000 rows : source="/opt/apache/log/access_combined.log"| head 10000 | table action, bytes, clientip

and I use ExportExcel module to export above result set, but I got 13,740 rows in excel ! I tried to search and export 1,000 rows , I will get correct results.

I don't know why.

Regards,

Owen

1 Solution

araitz
Splunk Employee
Splunk Employee

I am currently working on version 2.0, the road map for which is listed here: http://splunk-base.splunk.com/apps/29336/splunk-for-excel-export. I have reproduced a few cases where too many results were returned, or where multiline exports had partial _raw fields. I am working on fixing these issues for 2.0 as well.

EDIT: Version 2.0 was released on May 13th and includes several performance and stability improvements.

View solution in original post

araitz
Splunk Employee
Splunk Employee

I am currently working on version 2.0, the road map for which is listed here: http://splunk-base.splunk.com/apps/29336/splunk-for-excel-export. I have reproduced a few cases where too many results were returned, or where multiline exports had partial _raw fields. I am working on fixing these issues for 2.0 as well.

EDIT: Version 2.0 was released on May 13th and includes several performance and stability improvements.

Takajian
Builder

Addition to previous my comment, I used browser Google Chrome 17, Firefox 9, IE 9. Splunk OS is 4.3.1. I see this issue with any type of data. The platform is linux. Do you have any idea to solve the issue?

0 Karma

Takajian
Builder

In my case, I used chart and stats command. The result was 10 rows, but I exported over 100 rows with excel. The search command is like "sourcetype=xxxx | chart count by yyyy" or "sourcetype=xxxx | stats count by yyyy". I assume this issue can be reproduce on other splunk instances. If you need more info to reproduce the issue in your environment, please let me know.

0 Karma

araitz
Splunk Employee
Splunk Employee

I am working on reproducing the issues. Any additional information that you can provide with regard to the type of data and your browser and Splunk OS version would be awesome.

0 Karma

Takajian
Builder

I faced the same issue. The ExportExcel module exports incorrect search results. I hope this issue will be fixed soon.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...