<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Database lookup not returning all matches in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Database-lookup-not-returning-all-matches/m-p/156937#M185782</link>
    <description>&lt;P&gt;Hi. Yes, the subject of editing dblookup.conf and transforms.conf files to create a lookup that returns more than the default number of one match is covered here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/DBX/1.1.3/DeployDBX/Setupadatabaselookuptable#Create_a_lookup_by_editing_dblookup.conf"&gt;http://docs.splunk.com/Documentation/DBX/1.1.3/DeployDBX/Setupadatabaselookuptable#Create_a_lookup_by_editing_dblookup.conf&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Feb 2014 21:58:39 GMT</pubDate>
    <dc:creator>sroback_splunk</dc:creator>
    <dc:date>2014-02-19T21:58:39Z</dc:date>
    <item>
      <title>Database lookup not returning all matches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Database-lookup-not-returning-all-matches/m-p/156934#M185779</link>
      <description>&lt;P&gt;I have created a database lookup and have changed the maximum matches in the lookup defintion to 100, but only 1 match is being returned. I am using DB Connect 1.1.2 with an Oracle database.&lt;/P&gt;

&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2014 13:54:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Database-lookup-not-returning-all-matches/m-p/156934#M185779</guid>
      <dc:creator>sc0tt</dc:creator>
      <dc:date>2014-02-19T13:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Database lookup not returning all matches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Database-lookup-not-returning-all-matches/m-p/156935#M185780</link>
      <description>&lt;P&gt;You need to set &lt;CODE&gt;max_matches&lt;/CODE&gt; in the corresponding stanza in both transforms.conf and dblookup.conf. Have you restarted Splunk after making those changes?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2014 14:01:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Database-lookup-not-returning-all-matches/m-p/156935#M185780</guid>
      <dc:creator>ziegfried</dc:creator>
      <dc:date>2014-02-19T14:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: Database lookup not returning all matches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Database-lookup-not-returning-all-matches/m-p/156936#M185781</link>
      <description>&lt;P&gt;I did not edit the config files. I only made the change in the Lookup definitions via Splunk web. Adding &lt;CODE&gt;max_matches&lt;/CODE&gt; to dblookup.conf fixed the issue. Is it documented anywhere that you need to make changes to this file as well? Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2014 14:26:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Database-lookup-not-returning-all-matches/m-p/156936#M185781</guid>
      <dc:creator>sc0tt</dc:creator>
      <dc:date>2014-02-19T14:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Database lookup not returning all matches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Database-lookup-not-returning-all-matches/m-p/156937#M185782</link>
      <description>&lt;P&gt;Hi. Yes, the subject of editing dblookup.conf and transforms.conf files to create a lookup that returns more than the default number of one match is covered here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/DBX/1.1.3/DeployDBX/Setupadatabaselookuptable#Create_a_lookup_by_editing_dblookup.conf"&gt;http://docs.splunk.com/Documentation/DBX/1.1.3/DeployDBX/Setupadatabaselookuptable#Create_a_lookup_by_editing_dblookup.conf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2014 21:58:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Database-lookup-not-returning-all-matches/m-p/156937#M185782</guid>
      <dc:creator>sroback_splunk</dc:creator>
      <dc:date>2014-02-19T21:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: Database lookup not returning all matches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Database-lookup-not-returning-all-matches/m-p/156938#M185783</link>
      <description>&lt;P&gt;Hi, I have a lookup whose maximum match is 249. I've set the "max_matches" to 300 but the maximum it returns is only 99. Is it the limit? Are there any other settings I need to modify?  Any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2014 12:37:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Database-lookup-not-returning-all-matches/m-p/156938#M185783</guid>
      <dc:creator>karthi4k</dc:creator>
      <dc:date>2014-05-27T12:37:46Z</dc:date>
    </item>
  </channel>
</rss>

