<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to avoid this error &amp;quot;WARN  StatsProcessor - 'stats' command: limit for values of field 'user_id' reached.  Some values may have been truncated or ignored.&amp;quot; in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445800#M126449</link>
    <description>&lt;PRE&gt;&lt;CODE&gt;&amp;lt;query&amp;gt; 
|dedup user_id  |stats list("user_id") as User dc(user_id) as Total_No_User sum(bytes_in)  as Total_Bandwidth by  group | eventstats sum(bytes_in) as Total_Bandwidth by group | rename group AS "AD Group"
&amp;lt;/query&amp;gt;
    &amp;lt;/search&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Sat, 04 May 2019 15:33:19 GMT</pubDate>
    <dc:creator>su_kumar</dc:creator>
    <dc:date>2019-05-04T15:33:19Z</dc:date>
    <item>
      <title>how to avoid this error "WARN  StatsProcessor - 'stats' command: limit for values of field 'user_id' reached.  Some values may have been truncated or ignored."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445794#M126443</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am using the stats command with the list() function. , i am getting below error.&lt;/P&gt;

&lt;P&gt;Error :&lt;BR /&gt;
'stats' command: limit for values of field 'xxx' reached. Some values may have been truncated or ignored.&lt;/P&gt;

&lt;P&gt;WARN  StatsProcessor - 'stats' command: limit for values of field 'user_id' reached.  Some values may have been truncated or ignored.&lt;BR /&gt;
ERROR SearchParser - Missing a search command before '|'. Error at position '2086' of search query '| tstats count AS count sum(Web_Access_Event.bytes...{snipped} {errorcontext = main |    |dedup user}'.&lt;/P&gt;

&lt;P&gt;i have configured limit.conf&lt;BR /&gt;
[stats]&lt;BR /&gt;
list_maxsize = 10000&lt;BR /&gt;
maxresultrows = 50000&lt;BR /&gt;
maxvalues = 10000&lt;BR /&gt;
maxvaluesize = 10000&lt;BR /&gt;
Unfortunately , after setting in limit.conf , unable to fix this issue.&lt;BR /&gt;
anyone help me on this issue&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:24:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445794#M126443</guid>
      <dc:creator>su_kumar</dc:creator>
      <dc:date>2020-09-30T00:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: how to avoid this error "WARN  StatsProcessor - 'stats' command: limit for values of field 'user_id' reached.  Some values may have been truncated or ignored."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445795#M126444</link>
      <description>&lt;P&gt;Did you cycle Splunk after modifying limits.conf?&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 18:52:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445795#M126444</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2019-05-02T18:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: how to avoid this error "WARN  StatsProcessor - 'stats' command: limit for values of field 'user_id' reached.  Some values may have been truncated or ignored."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445796#M126445</link>
      <description>&lt;P&gt;if  you talking about after modify limits.conf , need to restart limilts.conf so after modify limits.conf , i had restarted splunk&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2019 03:50:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445796#M126445</guid>
      <dc:creator>su_kumar</dc:creator>
      <dc:date>2019-05-03T03:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: how to avoid this error "WARN  StatsProcessor - 'stats' command: limit for values of field 'user_id' reached.  Some values may have been truncated or ignored."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445797#M126446</link>
      <description>&lt;P&gt;can u please put your SPL which has stats function?&lt;BR /&gt;
I don't think it is a limits.conf issue as there might be improvement scope in the SPL&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2019 06:30:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445797#M126446</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2019-05-03T06:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: how to avoid this error "WARN  StatsProcessor - 'stats' command: limit for values of field 'user_id' reached.  Some values may have been truncated or ignored."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445798#M126447</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;

&lt;P&gt;Try this :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[stats]
list_maxsize = 10000
maxresultrows = 50000
maxvalues = 10000
maxvaluesize = 10000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;From here : &lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/132521/stats-command-limit-for-values-of-field-xxx-reached-some-values-may-have-been-truncated-or-ignored.html"&gt;https://answers.splunk.com/answers/132521/stats-command-limit-for-values-of-field-xxx-reached-some-values-may-have-been-truncated-or-ignored.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Seems like they have the same issue.&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
David&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2019 07:03:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445798#M126447</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-03T07:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: how to avoid this error "WARN  StatsProcessor - 'stats' command: limit for values of field 'user_id' reached.  Some values may have been truncated or ignored."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445799#M126448</link>
      <description>&lt;P&gt;You have an errant pipe in your search between main and dedup:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ERROR SearchParser - Missing a search command before '|'. Error at position '2086' of search query '| tstats count AS count sum(Web_Access_Event.bytes...{snipped} {errorcontext = main | |dedup user}'.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 03 May 2019 16:01:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445799#M126448</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2019-05-03T16:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: how to avoid this error "WARN  StatsProcessor - 'stats' command: limit for values of field 'user_id' reached.  Some values may have been truncated or ignored."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445800#M126449</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;&amp;lt;query&amp;gt; 
|dedup user_id  |stats list("user_id") as User dc(user_id) as Total_No_User sum(bytes_in)  as Total_Bandwidth by  group | eventstats sum(bytes_in) as Total_Bandwidth by group | rename group AS "AD Group"
&amp;lt;/query&amp;gt;
    &amp;lt;/search&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 04 May 2019 15:33:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445800#M126449</guid>
      <dc:creator>su_kumar</dc:creator>
      <dc:date>2019-05-04T15:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: how to avoid this error "WARN  StatsProcessor - 'stats' command: limit for values of field 'user_id' reached.  Some values may have been truncated or ignored."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445801#M126450</link>
      <description>&lt;P&gt;Hi ,&lt;BR /&gt;
below solution is not working :&lt;BR /&gt;
     [stats]&lt;BR /&gt;
     list_maxsize = 10000&lt;BR /&gt;
     maxresultrows = 50000&lt;BR /&gt;
     maxvalues = 10000&lt;BR /&gt;
     maxvaluesize = 10000&lt;/P&gt;</description>
      <pubDate>Sat, 04 May 2019 15:37:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445801#M126450</guid>
      <dc:creator>su_kumar</dc:creator>
      <dc:date>2019-05-04T15:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: how to avoid this error "WARN  StatsProcessor - 'stats' command: limit for values of field 'user_id' reached.  Some values may have been truncated or ignored."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445802#M126451</link>
      <description>&lt;P&gt;Oh,  if this is your query then you need to remove the pipe from in front of dedup and instead go for values function not the list function &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt; &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; |stats values("user_id") as User dc(user_id) as Total_No_User sum(bytes_in)  as Total_Bandwidth by  group | eventstats sum(bytes_in) as Total_Bandwidth by group | rename group AS "AD Group"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 04 May 2019 15:39:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445802#M126451</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-04T15:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: how to avoid this error "WARN  StatsProcessor - 'stats' command: limit for values of field 'user_id' reached.  Some values may have been truncated or ignored."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445803#M126452</link>
      <description>&lt;P&gt;I have removed pipe but still see errror and not able to see last column duration value&lt;/P&gt;

&lt;P&gt;latest query:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;dedup user_id | eval duration = round(duration,2) | eval duration=tostring(duration,"duration") | sort group,user_id | where bytes_in &amp;gt;0 |stats list("user_id") as User,list("dest_domain") as Application,list("bytes_in") as Bandwidth_used, list("duration") as Time by group
| rename group AS "AD Group"
&amp;lt;/query&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;warning :&lt;BR /&gt;
19 08:46:33.559 -0700 WARN  StatsProcessor - Specified field(s) missing from results: 'duration'&lt;BR /&gt;
05-08-2019 08:46:33.890 -0700 WARN  StatsProcessor - 'stats' command: limit for values of field 'user_id' reached.  Some values may have been truncated or ignored.&lt;BR /&gt;
05-08-2019 08:46:34.153 -0700 WARN  StatsProcessor - Specified field(s) missing from results: 'duration'&lt;BR /&gt;
05-08-2019 08:46:36.159 -0700 WARN  DispatchManager - The instance is approaching the maximum number of historical searches that can be run concurrently.&lt;BR /&gt;
05-08-2019 08:46:36.182 -0700 WARN  DispatchManager - The instance is approaching the maximum number of historical searches that can be run concurrently&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 09:38:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445803#M126452</guid>
      <dc:creator>su_kumar</dc:creator>
      <dc:date>2019-05-08T09:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: how to avoid this error "WARN  StatsProcessor - 'stats' command: limit for values of field 'user_id' reached.  Some values may have been truncated or ignored."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445804#M126453</link>
      <description>&lt;P&gt;@su_kumar did this work for you using values instead of list?&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 09:49:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445804#M126453</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-08T09:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: how to avoid this error "WARN  StatsProcessor - 'stats' command: limit for values of field 'user_id' reached.  Some values may have been truncated or ignored."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445805#M126454</link>
      <description>&lt;P&gt;can you please try changing your query to&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| stats sum(bytes_in) as Total_Bandwidth_User_group dc(user_id) as Total_No_User  by user_id, group
| eventstats sum(Total_Bandwidth_User_group) as Total_Bandwidth by group 
| rename group AS "AD Group"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 08 May 2019 10:43:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445805#M126454</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2019-05-08T10:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: how to avoid this error "WARN  StatsProcessor - 'stats' command: limit for values of field 'user_id' reached.  Some values may have been truncated or ignored."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445806#M126455</link>
      <description>&lt;P&gt;Replace with the new query I posted here :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|stats values("user_id") as User dc(user_id) as Total_No_User sum(bytes_in)  as Total_Bandwidth by  group | eventstats sum(bytes_in) as Total_Bandwidth by group | rename group AS "AD Group"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 08 May 2019 13:59:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-avoid-this-error-quot-WARN-StatsProcessor-stats-command/m-p/445806#M126455</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-08T13:59:05Z</dc:date>
    </item>
  </channel>
</rss>

