As of Splunk 4.3, you can now export an unlimited number of events from the UI. Do note, however, that exporting too many events in that manner (typically, several millions) could cause Splunkweb to misbehave and possibly to become temporarily unresponsive.
If you really need to often export large number of events, we would still recommend the use of the outputcsv command and/or to run the search from the CLI.
As of Splunk 4.3, you can now export an unlimited number of events from the UI. Do note, however, that exporting too many events in that manner (typically, several millions) could cause Splunkweb to misbehave and possibly to become temporarily unresponsive.
If you really need to often export large number of events, we would still recommend the use of the outputcsv command and/or to run the search from the CLI.
@bob999 : The csv row limit for the email alert action is indeed completely unrelated to the csv export row limit in the flashtimeline which is discussed here. I believe that the limits.conf setting that you found is pertinent to your problem, although action.email.maxresults in savedsearches.conf is probably more so.
Hexx, Pease can you confirm this is fixed in 4.3? i have a scheduled saved search which emails results with CSV of results as its alert action. it seems to be truncating at 10000 rows.
This one comment by you is the only mention that this has been changed in 4.3, however i am running 4.3.1 and am still having the issue!
Could this be the reason?
limits.conf
[scheduler]
max_action_results =
* The maximum number of results to load when triggering >an alert action.
* Defaults to 10000
?
Splunk for Excel Export will allow you to export more than 10K results: