<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: max search length in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/max-search-length/m-p/46671#M959</link>
    <description>&lt;P&gt;splunkd has some failure modes I'm sure for searches above some size, even if just performance issues or ungainly handling, but several hundred kilobyte searches work just fine.&lt;/P&gt;

&lt;P&gt;The problem you're seeing is happening in splunkweb.  I suspect it's some kind of quoting failure, rather than a length issue.  If the exact string isn't sensitive, I'd love to reproduce and file the bug.  A support ticket would be appropriate.&lt;/P&gt;

&lt;P&gt;As a lame workaround, manually adding the search to a savedsearches.conf file will likely bypass the problem.&lt;/P&gt;</description>
    <pubDate>Fri, 10 Sep 2010 01:31:26 GMT</pubDate>
    <dc:creator>jrodman</dc:creator>
    <dc:date>2010-09-10T01:31:26Z</dc:date>
    <item>
      <title>max search length</title>
      <link>https://community.splunk.com/t5/Reporting/max-search-length/m-p/46670#M958</link>
      <description>&lt;P&gt;Is there any limitation of search length?
I've made almost 5000 bytes search commands in Splunk &amp;gt; Search, tried to save it, but met an error;&lt;/P&gt;

&lt;P&gt;500 Internal Server Error
XMLSyntaxError: Start tag expected, '&amp;lt;' not found, line 1, column 1&lt;/P&gt;

&lt;P&gt;Is there any way to avoid this other than not changing search command.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Sep 2010 15:52:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/max-search-length/m-p/46670#M958</guid>
      <dc:creator>kondou</dc:creator>
      <dc:date>2010-09-09T15:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: max search length</title>
      <link>https://community.splunk.com/t5/Reporting/max-search-length/m-p/46671#M959</link>
      <description>&lt;P&gt;splunkd has some failure modes I'm sure for searches above some size, even if just performance issues or ungainly handling, but several hundred kilobyte searches work just fine.&lt;/P&gt;

&lt;P&gt;The problem you're seeing is happening in splunkweb.  I suspect it's some kind of quoting failure, rather than a length issue.  If the exact string isn't sensitive, I'd love to reproduce and file the bug.  A support ticket would be appropriate.&lt;/P&gt;

&lt;P&gt;As a lame workaround, manually adding the search to a savedsearches.conf file will likely bypass the problem.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2010 01:31:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/max-search-length/m-p/46671#M959</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2010-09-10T01:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: max search length</title>
      <link>https://community.splunk.com/t5/Reporting/max-search-length/m-p/46672#M960</link>
      <description>&lt;P&gt;Yes, the problem always happens in splunk web.  I think you should be able to reproduce by creating over 5000 bytes search.&lt;/P&gt;

&lt;P&gt;And, my workaround is almost the same as what you are saying.  I just new entry in create search and report, which includes the search line, also with non error search entry.  I call non search&lt;BR /&gt;
entry from search and report tab, and then paste THAT error search, which gives me what I want.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2010 15:25:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/max-search-length/m-p/46672#M960</guid>
      <dc:creator>kondou</dc:creator>
      <dc:date>2010-09-13T15:25:46Z</dc:date>
    </item>
  </channel>
</rss>

