<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stop email truncate? in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Stop-email-truncate/m-p/24075#M440</link>
    <description>&lt;P&gt;The maximum is 10000 by default. I would ask you to think very hard about whether you really want a file with more than 10000 items sent to you, and what use you would make of such a file (that might not be better done by fetching the results directly from Splunk). Nevertheless, you can change the limit by setting &lt;CODE&gt;action.email.maxresults&lt;/CODE&gt; under the saved search's settings in &lt;CODE&gt;savedsearches.conf&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/admin/savedsearchesconf"&gt;http://docs.splunk.com/Documentation/Splunk/latest/admin/savedsearchesconf&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Apr 2012 05:04:34 GMT</pubDate>
    <dc:creator>gkanapathy</dc:creator>
    <dc:date>2012-04-11T05:04:34Z</dc:date>
    <item>
      <title>Stop email truncate?</title>
      <link>https://community.splunk.com/t5/Reporting/Stop-email-truncate/m-p/24074#M439</link>
      <description>&lt;P&gt;I have a saved search that's running properly and alerts being sent at the appropriate times, but unfortunately the data being sent in email is truncated; hence the message in the email:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;NOTE: Search results in this email might have been truncated. Please visit the search job page to view the full resultset
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Is there a way to overcome this limitation? &lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2012 02:07:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Stop-email-truncate/m-p/24074#M439</guid>
      <dc:creator>freitagb</dc:creator>
      <dc:date>2012-04-11T02:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: Stop email truncate?</title>
      <link>https://community.splunk.com/t5/Reporting/Stop-email-truncate/m-p/24075#M440</link>
      <description>&lt;P&gt;The maximum is 10000 by default. I would ask you to think very hard about whether you really want a file with more than 10000 items sent to you, and what use you would make of such a file (that might not be better done by fetching the results directly from Splunk). Nevertheless, you can change the limit by setting &lt;CODE&gt;action.email.maxresults&lt;/CODE&gt; under the saved search's settings in &lt;CODE&gt;savedsearches.conf&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/admin/savedsearchesconf"&gt;http://docs.splunk.com/Documentation/Splunk/latest/admin/savedsearchesconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2012 05:04:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Stop-email-truncate/m-p/24075#M440</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2012-04-11T05:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Stop email truncate?</title>
      <link>https://community.splunk.com/t5/Reporting/Stop-email-truncate/m-p/24076#M441</link>
      <description>&lt;P&gt;If your output is greater than 50,000 rows, the above change to savedsearches.conf  may also need to be paired with a change to limits.conf stanza:&lt;/P&gt;

&lt;P&gt;max_action_results = &lt;BR /&gt;
 * The maximum number of results to load when triggering an alert action.&lt;BR /&gt;
 * Defaults to 50000&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.2/Admin/Limitsconf" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.2/Admin/Limitsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I'd also strongly suggest only making changes to this stanza with excessive caution since it's a global setting that's not restricted per-search.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:36:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Stop-email-truncate/m-p/24076#M441</guid>
      <dc:creator>kearaspoor</dc:creator>
      <dc:date>2020-09-29T10:36:38Z</dc:date>
    </item>
  </channel>
</rss>

