<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dashboard Saved search results is being truncated to 1000 in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137664#M8244</link>
    <description>&lt;P&gt;MuS,&lt;BR /&gt;
   I created a new Dashboard and added the search. It worked ! So I made the new Dashboard similar to the other that doesn't work.&lt;/P&gt;

&lt;P&gt;With my user I can see the chart, but with another user, when loading message reaches 71%, the process is aborted and the same message is shown. All other charts are processes.&lt;/P&gt;

&lt;P&gt;Chart working: &lt;A href="http://imageshack.com/a/img824/2297/uslk.png"&gt;http://imageshack.com/a/img824/2297/uslk.png&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Nov 2013 16:52:31 GMT</pubDate>
    <dc:creator>alexantao</dc:creator>
    <dc:date>2013-11-13T16:52:31Z</dc:date>
    <item>
      <title>Dashboard Saved search results is being truncated to 1000</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137659#M8239</link>
      <description>&lt;P&gt;I built a Saved Search and configured a Dashboard to include that Saved Search (below). In a panel of this Dashboard, I configured a report based on this saved search.&lt;/P&gt;

&lt;P&gt;When I load the Dashboard, the search is started and stops showing NO data and a message below the graphic said that the results were truncated, and No data is shown. Opening in search I get a lot of results in events....&lt;/P&gt;

&lt;P&gt;The Saved Search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=acess_web |eval Gb=bytes_in/1073741824| timechart span=1d sum(Gb) 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Screenshot: &lt;/P&gt;

&lt;P&gt;imageshack.com/a/img571/9028/ddaw.png&lt;/P&gt;

&lt;P&gt;Thanks for any help&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2013 21:09:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137659#M8239</guid>
      <dc:creator>alexantao</dc:creator>
      <dc:date>2013-11-11T21:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Saved search results is being truncated to 1000</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137660#M8240</link>
      <description>&lt;P&gt;What is the earliest and latest value for the dashboard?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2013 00:25:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137660#M8240</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2013-11-12T00:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Saved search results is being truncated to 1000</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137661#M8241</link>
      <description>&lt;P&gt;The Visualisation must show 1 month of logs, with 1 day of span. In teory, the visualisation should have only 30 points, each one is one day, and the data is the sum of Gb transfered that day.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2013 10:53:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137661#M8241</guid>
      <dc:creator>alexantao</dc:creator>
      <dc:date>2013-11-12T10:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Saved search results is being truncated to 1000</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137662#M8242</link>
      <description>&lt;P&gt;if you run this search in the search app:&lt;/P&gt;

&lt;P&gt;index=acess_web |eval Gb=bytes_in/1073741824| timechart span=1d sum(Gb)&lt;/P&gt;

&lt;P&gt;do you get back any results? Do you have any field named 'bytes_in'?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:16:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137662#M8242</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2020-09-28T15:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Saved search results is being truncated to 1000</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137663#M8243</link>
      <description>&lt;P&gt;How many rows are you getting while running this query in search app? In ideal situation, if your selected timerange (in both search app and in your dashboard) should be set to show one month data. If nothing is specified if will run for All Times and may result more than 30 rows.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2013 16:39:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137663#M8243</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2013-11-13T16:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Saved search results is being truncated to 1000</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137664#M8244</link>
      <description>&lt;P&gt;MuS,&lt;BR /&gt;
   I created a new Dashboard and added the search. It worked ! So I made the new Dashboard similar to the other that doesn't work.&lt;/P&gt;

&lt;P&gt;With my user I can see the chart, but with another user, when loading message reaches 71%, the process is aborted and the same message is shown. All other charts are processes.&lt;/P&gt;

&lt;P&gt;Chart working: &lt;A href="http://imageshack.com/a/img824/2297/uslk.png"&gt;http://imageshack.com/a/img824/2297/uslk.png&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2013 16:52:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137664#M8244</guid>
      <dc:creator>alexantao</dc:creator>
      <dc:date>2013-11-13T16:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Saved search results is being truncated to 1000</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137665#M8245</link>
      <description>&lt;P&gt;Somesoni2, for now, I'm getting 20 rows. But the maximum I'm planning is for the role month, or 31 rows.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2013 17:27:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137665#M8245</guid>
      <dc:creator>alexantao</dc:creator>
      <dc:date>2013-11-13T17:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Saved search results is being truncated to 1000</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137666#M8246</link>
      <description>&lt;P&gt;Update: after the saved search ran on background (programed to run at midnight), it stopped working again, for all users. &lt;BR /&gt;
With the user I created the dashboard, entered the Edit Panel and then, the Statistics mode. It is listing dates since January. There are more than 500 pages of data. &lt;BR /&gt;
But it should not happen, since I configured to count the events from only 1 month ago ( -1mon, now).&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2013 09:38:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137666#M8246</guid>
      <dc:creator>alexantao</dc:creator>
      <dc:date>2013-11-14T09:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Saved search results is being truncated to 1000</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137667#M8247</link>
      <description>&lt;P&gt;Tried to put earliest=-mon on search string but didn't work (same results).&lt;BR /&gt;
The strange is that, when I try the search mannually, on the result table for 1 second apears a bunh of rows with all dates and then disapear, showing only the results (correct results) from the search.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2013 11:21:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137667#M8247</guid>
      <dc:creator>alexantao</dc:creator>
      <dc:date>2013-11-14T11:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Saved search results is being truncated to 1000</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137668#M8248</link>
      <description>&lt;P&gt;I'm encountering the same issue using PDF report.  The view (dashboard) displays all the results just fine.  A manual preview generates a PDF that displays only 1000 lines when there should be many more lines.  This started after our upgrade to 5.0.3 (from version 4.3.x).&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2013 17:32:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137668#M8248</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2013-12-12T17:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Saved search results is being truncated to 1000</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137669#M8249</link>
      <description>&lt;P&gt;Have you opened a support case for this? We are trying to get Splunk to remove this limit and more customers behind this will help drive this.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Ken&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 15:12:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dashboard-Saved-search-results-is-being-truncated-to-1000/m-p/137669#M8249</guid>
      <dc:creator>kbecker</dc:creator>
      <dc:date>2016-09-29T15:12:45Z</dc:date>
    </item>
  </channel>
</rss>

