Splunk Search

Saved Search only return 1000 rows

splunkgam
New Member

When a saved search sends an email with the results in a CSV file, the file never contains more than 1000 lines (plus the header line). How can I change this behavior to contain all the results found in the search, for instance 12000. When I run the same exact search manually in splunk, it returns 12000 rows, but the file will only contain 1000.

Tags (3)
0 Karma

Ayn
Legend

You should be able to modify the default limit of 1000 events by setting another value for maxresults in alert_actions.conf. See this question: http://splunk-base.splunk.com/answers/7544/splunk-alert-only-includes-first-1000-results-of-search-w...

splunkgam
New Member

Updating both default and local alert_actions.conf did not change the behavior. I did notice in the link you provided that one of the posters thought it might be because they were using 4.1.5 and that may have been part of the problem. We are using 4.1.4.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...