Splunk Search

Is there a setting to increase the "results per page" value when you show source?

Jeremiah
Motivator

When I go to show source on an event, the maximum number of results I can display is 1000 (the "Results per page" dropdown). Is there a setting to increase this value?

Tags (2)
0 Karma
1 Solution

Stephen_Sorkin
Splunk Employee
Splunk Employee

These options are loaded from $SPLUNK_HOME/etc/apps/search/default/data/ui/views/show_source.xml. You could tune this by placing an edited version of this file in $SPLUNK_HOME/etc/apps/search/local/data/ui/views/show_source.xml. However, there's an implicit limit on the number of events that can be retrieved based on a time bound around the target event, which in 4.1.x is 1 day.

View solution in original post

teh21
New Member

Does anyone know what needs added/changed in the show_source.xml file to raise this limit? My file doesn't have anything specifying any values at all.

0 Karma

yannK
Splunk Employee
Splunk Employee

you can edit the view directly in the UI and add your limits.

search app
ui > view > showsource > edit xml

0 Karma

Stephen_Sorkin
Splunk Employee
Splunk Employee

These options are loaded from $SPLUNK_HOME/etc/apps/search/default/data/ui/views/show_source.xml. You could tune this by placing an edited version of this file in $SPLUNK_HOME/etc/apps/search/local/data/ui/views/show_source.xml. However, there's an implicit limit on the number of events that can be retrieved based on a time bound around the target event, which in 4.1.x is 1 day.

Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...