<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query Limit on a UI view? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Query-Limit-on-a-UI-view/m-p/26922#M1043</link>
    <description>&lt;P&gt;Post process is limited to 10,000 events.  If you want the full amount you can split into unique searches.&lt;/P&gt;

&lt;P&gt;Some values are configurable in &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Limitsconf"&gt;limits.conf&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jun 2011 22:49:09 GMT</pubDate>
    <dc:creator>melting</dc:creator>
    <dc:date>2011-06-13T22:49:09Z</dc:date>
    <item>
      <title>Query Limit on a UI view?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Query-Limit-on-a-UI-view/m-p/26921#M1042</link>
      <description>&lt;P&gt;I've built a very small example to reproduce a problem I am having.   Using this page as an example:&lt;BR /&gt;
&lt;A href="http://www.splunk.com/base/Documentation/4.2.1/Developer/FormSearchPostProcess"&gt;http://www.splunk.com/base/Documentation/4.2.1/Developer/FormSearchPostProcess&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I've built a dashboard that looks like this:&lt;BR /&gt;
    &lt;/P&gt;&lt;FORM&gt;&lt;BR /&gt;
      &lt;LABEL&gt;Requests search&lt;/LABEL&gt;&lt;P&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  &amp;lt;searchTemplate&amp;gt;sourcetype="Exchange2010" sender="$sender$"&amp;lt;/searchTemplate&amp;gt;

  &amp;lt;fieldset&amp;gt;
    &amp;lt;input type="text" token="sender"&amp;gt;
      &amp;lt;label&amp;gt;Sender&amp;lt;/label&amp;gt;
      &amp;lt;seed&amp;gt;*&amp;lt;/seed&amp;gt;
    &amp;lt;/input&amp;gt;

    &amp;lt;input type="time"&amp;gt;
    &amp;lt;default&amp;gt;Last 30 days&amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;

  &amp;lt;row&amp;gt;
    &amp;lt;chart&amp;gt;
      &amp;lt;title&amp;gt;Requests over time for result set&amp;lt;/title&amp;gt;
      &amp;lt;searchPostProcess&amp;gt;timechart count as "Requests"&amp;lt;/searchPostProcess&amp;gt;
      &amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;
    &amp;lt;/chart&amp;gt;
  &amp;lt;/row&amp;gt;

  &amp;lt;row&amp;gt;
    &amp;lt;chart&amp;gt;
      &amp;lt;title&amp;gt;Top users in result set&amp;lt;/title&amp;gt;
      &amp;lt;searchPostProcess&amp;gt;top 10 recipient&amp;lt;/searchPostProcess&amp;gt;
      &amp;lt;option name="charting.chart"&amp;gt;pie&amp;lt;/option&amp;gt;
    &amp;lt;/chart&amp;gt;

  &amp;lt;/row&amp;gt;

  &amp;lt;row&amp;gt;
    &amp;lt;table&amp;gt;
      &amp;lt;title&amp;gt;Requests in result set&amp;lt;/title&amp;gt;
      &amp;lt;searchPostProcess&amp;gt;sort - _time | fields _time, sender, recipient&amp;lt;/searchPostProcess&amp;gt;
      &amp;lt;fields&amp;gt;_time, sender, recipient&amp;lt;/fields&amp;gt;
      &amp;lt;option name="showPager"&amp;gt;true&amp;lt;/option&amp;gt;
      &amp;lt;option name="count"&amp;gt;30&amp;lt;/option&amp;gt;
      &amp;lt;option name="displayRowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Regardless of the "Time" chosen, the query seems to abort just after hitting 10,000 rows.&lt;BR /&gt;
Is this a known limitation? Is there a configuration change I can make to get more?&lt;BR /&gt;
In some instances, this is only good for a day or two of data, and after that short data. for instance, I can select 30 days, but I really only get about 6.&lt;/P&gt;

&lt;P&gt;It always seems to stop short.  I'm not sure why, but I never get more than 13,000 records.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;&lt;/FORM&gt;</description>
      <pubDate>Mon, 13 Jun 2011 18:12:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Query-Limit-on-a-UI-view/m-p/26921#M1042</guid>
      <dc:creator>jgauthier</dc:creator>
      <dc:date>2011-06-13T18:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Query Limit on a UI view?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Query-Limit-on-a-UI-view/m-p/26922#M1043</link>
      <description>&lt;P&gt;Post process is limited to 10,000 events.  If you want the full amount you can split into unique searches.&lt;/P&gt;

&lt;P&gt;Some values are configurable in &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Limitsconf"&gt;limits.conf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2011 22:49:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Query-Limit-on-a-UI-view/m-p/26922#M1043</guid>
      <dc:creator>melting</dc:creator>
      <dc:date>2011-06-13T22:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: Query Limit on a UI view?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Query-Limit-on-a-UI-view/m-p/26923#M1044</link>
      <description>&lt;P&gt;I'm not sure I understand "split into unique searches." and how it applies to this.  Could you elaborate?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2011 12:44:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Query-Limit-on-a-UI-view/m-p/26923#M1044</guid>
      <dc:creator>jgauthier</dc:creator>
      <dc:date>2011-06-14T12:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Query Limit on a UI view?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Query-Limit-on-a-UI-view/m-p/26924#M1045</link>
      <description>&lt;P&gt;@jgauthier - He's saying instead of doing a single searchTemplate and then searchPostProcess for each chart, get rid of searchPostProcess and do a searchTemplate within each chart.  It means you're going to run more searches, but ultimately will be able to surpass the 10,000 event limit.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2012 13:42:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Query-Limit-on-a-UI-view/m-p/26924#M1045</guid>
      <dc:creator>swdonline</dc:creator>
      <dc:date>2012-01-30T13:42:02Z</dc:date>
    </item>
  </channel>
</rss>

