<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Subsearch limits pre-post filtering? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Subsearch-limits-pre-post-filtering/m-p/690962#M235318</link>
    <description>&lt;P&gt;I've seen the &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/Search/Aboutsubsearches" target="_self"&gt;documentation&lt;/A&gt; which says "by default subsearches return a maximum of 10,000 results and have a maximum runtime of 60 seconds", but it's unclear if that limit is before or after applying transforms.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;e.g. does it apply to the base search (e.g. the output of index=wineventlogs AND ComputerName=MyDesktop is capped at 10k) or if the filtered results (e.g. if I add conditions and filter to reduce the final dataset) is where any results over 10k will be dropped?&lt;/P&gt;</description>
    <pubDate>Tue, 18 Jun 2024 07:22:51 GMT</pubDate>
    <dc:creator>quadrant8</dc:creator>
    <dc:date>2024-06-18T07:22:51Z</dc:date>
    <item>
      <title>Subsearch limits pre-post filtering?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Subsearch-limits-pre-post-filtering/m-p/690962#M235318</link>
      <description>&lt;P&gt;I've seen the &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/Search/Aboutsubsearches" target="_self"&gt;documentation&lt;/A&gt; which says "by default subsearches return a maximum of 10,000 results and have a maximum runtime of 60 seconds", but it's unclear if that limit is before or after applying transforms.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;e.g. does it apply to the base search (e.g. the output of index=wineventlogs AND ComputerName=MyDesktop is capped at 10k) or if the filtered results (e.g. if I add conditions and filter to reduce the final dataset) is where any results over 10k will be dropped?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 07:22:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Subsearch-limits-pre-post-filtering/m-p/690962#M235318</guid>
      <dc:creator>quadrant8</dc:creator>
      <dc:date>2024-06-18T07:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: Subsearch limits pre-post filtering?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Subsearch-limits-pre-post-filtering/m-p/690971#M235320</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194063"&gt;@quadrant8&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;10k events is the limit of subsearch results: if you run the subsearch as a main search, without anithing, have you more or less of 10K events?&lt;/P&gt;&lt;P&gt;if more than 10K events, you have to find a different solution (e.g. putting the subsearch in the main search with an OR condition, defining a correlation key and checking that the correlation key is present in both the searches.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 08:32:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Subsearch-limits-pre-post-filtering/m-p/690971#M235320</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-06-18T08:32:38Z</dc:date>
    </item>
  </channel>
</rss>

