<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Upload large file in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/693955#M236060</link>
    <description>&lt;P&gt;You can find it here..&lt;/P&gt;&lt;P&gt;For list of all config files&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.2/Admin/Listofconfigurationfiles" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.2/Admin/Listofconfigurationfiles&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jul 2024 11:45:06 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2024-07-22T11:45:06Z</dc:date>
    <item>
      <title>Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267461#M80466</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;How does one upload files larger than 500mb? I get an error "File too large. The file selected is 996Mb. Maximum file size is 500Mb" Is this due to using the trial ?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 16:23:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267461#M80466</guid>
      <dc:creator>mwdbhyat</dc:creator>
      <dc:date>2016-09-07T16:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267462#M80467</link>
      <description>&lt;P&gt;The 500MB limit is for uploading file from Splunk Web, regardless of the license type.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.3/Data/Uploaddata"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.3/Data/Uploaddata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 16:27:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267462#M80467</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-09-07T16:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267463#M80468</link>
      <description>&lt;P&gt;Yes, both the trial and free licenses have an indexing limit of 500MB a day. For file upload on any license, the maximum file size is 500 MB, as the UI indicates.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 16:28:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267463#M80468</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2016-09-07T16:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267464#M80469</link>
      <description>&lt;P&gt;I've had the same problem.  You can use the Linux SPLIT command to break the file up into smaller parts&lt;/P&gt;

&lt;P&gt;&lt;A href="http://askubuntu.com/questions/54579/how-to-split-larger-files-into-smaller-parts"&gt;http://askubuntu.com/questions/54579/how-to-split-larger-files-into-smaller-parts&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 16:38:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267464#M80469</guid>
      <dc:creator>dbcase</dc:creator>
      <dc:date>2016-09-07T16:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267465#M80470</link>
      <description>&lt;P&gt;Thanks - Is there a way around this without using the Web, not splitting the file ? &lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 17:03:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267465#M80470</guid>
      <dc:creator>mwdbhyat</dc:creator>
      <dc:date>2016-09-07T17:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267466#M80471</link>
      <description>&lt;P&gt;I don't think so but you could try using the universal forwarder instead of uploading the file&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 17:06:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267466#M80471</guid>
      <dc:creator>dbcase</dc:creator>
      <dc:date>2016-09-07T17:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267467#M80472</link>
      <description>&lt;P&gt;Is it possible to zip the file so it is less than 500MB?&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/279/does-splunk-index-gzip-files.html"&gt;https://answers.splunk.com/answers/279/does-splunk-index-gzip-files.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 17:08:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267467#M80472</guid>
      <dc:creator>dbcase</dc:creator>
      <dc:date>2016-09-07T17:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267468#M80473</link>
      <description>&lt;P&gt;Figured it out with the CLI.. did a oneshot monitor. &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.2/Data/MonitorfilesanddirectoriesusingtheCLI"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.2/Data/MonitorfilesanddirectoriesusingtheCLI&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 17:29:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267468#M80473</guid>
      <dc:creator>mwdbhyat</dc:creator>
      <dc:date>2016-09-07T17:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267469#M80474</link>
      <description>&lt;P&gt;Ah good to know, haven't used that before &lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 17:31:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/267469#M80474</guid>
      <dc:creator>dbcase</dc:creator>
      <dc:date>2016-09-07T17:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/682198#M233067</link>
      <description>&lt;P&gt;For people finding this question in the years after 2016, you can set the max_upload_size setting in web.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[settings]
# set to the MB max
max_upload_size = 500
# you can also set a larger splunkdConnectionTimeout value so it wont timeout when uploading
splunkdConnectionTimeout=600&lt;/LI-CODE&gt;&lt;P&gt;ref: &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.0/Admin/Webconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.0/Admin/Webconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 22:04:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/682198#M233067</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-03-27T22:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/693922#M236053</link>
      <description>&lt;P&gt;btw, where can i find web.conf in windows?&lt;/P&gt;&lt;P&gt;Because i cant find the right one to edit this file&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 03:38:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/693922#M236053</guid>
      <dc:creator>Rizqi_Iskandar</dc:creator>
      <dc:date>2024-07-22T03:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/693955#M236060</link>
      <description>&lt;P&gt;You can find it here..&lt;/P&gt;&lt;P&gt;For list of all config files&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.2/Admin/Listofconfigurationfiles" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.2/Admin/Listofconfigurationfiles&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 11:45:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/693955#M236060</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-07-22T11:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/693978#M236068</link>
      <description>&lt;P&gt;I have edit the max_upload size from 500 to 8000 but still it cant upload enterprise security.&lt;/P&gt;&lt;P&gt;I try this way repeatly and restart splunk everytime i save this configuration, but nothing happen&lt;/P&gt;&lt;P&gt;Do you have other way to install splunk ES on windows?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 14:45:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/693978#M236068</guid>
      <dc:creator>Rizqi_Iskandar</dc:creator>
      <dc:date>2024-07-22T14:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/693995#M236070</link>
      <description>&lt;P&gt;What happens if you run btool on the settings stanza and grep for max_upload_size?&lt;/P&gt;&lt;P&gt;e.g.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/splunk/bin/splunk btool web list settings | grep max_upload&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it shows a value other than 8000, then likely your web.conf file is in the wrong place, or being overridden by another.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 18:54:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/693995#M236070</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-07-22T18:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/694009#M236073</link>
      <description>&lt;P&gt;I think this is happen because its run on Windows&lt;/P&gt;&lt;P&gt;I will try to install it on Linux first and i will let you know if the problem fixed&lt;/P&gt;&lt;P&gt;thanks for the help dude&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 21:57:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/694009#M236073</guid>
      <dc:creator>Rizqi_Iskandar</dc:creator>
      <dc:date>2024-07-22T21:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/694105#M236102</link>
      <description>&lt;P&gt;Sorry, I am too used to Linux. I believe the equivalent btool command on windows is:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;$splunkhome$/bin/splunk.exe btool web list settings | FINDSTR max_upload&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 20:19:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/694105#M236102</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-07-23T20:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/759094#M243333</link>
      <description>&lt;P&gt;The default upload size for files in Splunk is 500Mb to consider the browser memory usage. The good part is that this can be altered, as admins usually upload files 10 to 50 Gb in size using CLI ingestion.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The command below can be used to change the upload size to 2Gb. Note - run the CMD as administrator.&lt;BR /&gt;&lt;BR /&gt;echo [settings] &amp;gt; "C:\Program Files\Splunk\etc\system\local\web.conf"&lt;BR /&gt;echo max_upload_size = 2048 &amp;gt;&amp;gt; "C:\Program Files\Splunk\etc\system\local\web.conf"&lt;BR /&gt;&lt;BR /&gt;size can be increased by increasing the limit. Post this restart the Splunk.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;cd "C:\Program Files\Splunk\bin"&lt;BR /&gt;splunk restart&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Mar 2026 21:13:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/759094#M243333</guid>
      <dc:creator>AceAxis</dc:creator>
      <dc:date>2026-03-07T21:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: Upload large file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/759111#M243338</link>
      <description>&lt;H1&gt;&lt;STRONG&gt;Don't do that!&lt;/STRONG&gt;&lt;/H1&gt;&lt;P&gt;Firstly, it's not a good practice to put settings into system/local except for very few settings which are really, really local.&lt;/P&gt;&lt;P&gt;But most importantly, if you run the supplied commands, they will overwrite any settings you might have already had there! (and while it's not the best practice, people often put some stuff there; like cert definitions).&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2026 21:53:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Upload-large-file/m-p/759111#M243338</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-03-08T21:53:43Z</dc:date>
    </item>
  </channel>
</rss>

