<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Search limits results to 1000 events only in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132875#M36279</link>
    <description>&lt;P&gt;and you're seeing the result in Events tab or Visualization tab? What do you want to do with the data returned?&lt;/P&gt;</description>
    <pubDate>Fri, 19 Sep 2014 21:25:27 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2014-09-19T21:25:27Z</dc:date>
    <item>
      <title>Splunk Search limits results to 1000 events only</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132871#M36275</link>
      <description>&lt;P&gt;The following Search command:&lt;/P&gt;

&lt;P&gt;error OR failed OR severe OR ( sourcetype=access_* ( 404 OR 500 OR 503 ) )&lt;/P&gt;

&lt;P&gt;results to only 1000 events. A bang displays the following message:&lt;/P&gt;

&lt;P&gt;"Currently displaying the most recent 1000 events in the selected range. Select a narrower range or zoom in to see more events"&lt;/P&gt;

&lt;P&gt;Objective: to see all events in the last 24 hours .&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;UA&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 16:22:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132871#M36275</guid>
      <dc:creator>uayub</dc:creator>
      <dc:date>2014-09-19T16:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search limits results to 1000 events only</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132872#M36276</link>
      <description>&lt;P&gt;What was the time range selected in the timerange picker. Meanwhile, try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;error OR failed OR severe OR ( sourcetype=access_* ( 404 OR 500 OR 503 ) ) earliest=-24h@h
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 19 Sep 2014 19:44:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132872#M36276</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-09-19T19:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search limits results to 1000 events only</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132873#M36277</link>
      <description>&lt;P&gt;The time range was past 24 hours&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 21:12:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132873#M36277</guid>
      <dc:creator>uayub</dc:creator>
      <dc:date>2014-09-19T21:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search limits results to 1000 events only</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132874#M36278</link>
      <description>&lt;P&gt;Same error was observed. I am sure there might be a limit set up in one of the config files.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 21:15:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132874#M36278</guid>
      <dc:creator>uayub</dc:creator>
      <dc:date>2014-09-19T21:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search limits results to 1000 events only</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132875#M36279</link>
      <description>&lt;P&gt;and you're seeing the result in Events tab or Visualization tab? What do you want to do with the data returned?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 21:25:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132875#M36279</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-09-19T21:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search limits results to 1000 events only</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132876#M36280</link>
      <description>&lt;P&gt;in the Events tab. I normally would like to see all errors for the last 24 hours. I browse through these to see if anything critical has occurred.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 21:53:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132876#M36280</guid>
      <dc:creator>uayub</dc:creator>
      <dc:date>2014-09-19T21:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search limits results to 1000 events only</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132877#M36281</link>
      <description>&lt;P&gt;At the end of your search add this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| table * 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will cause splunk to return "results" instead of "events", and the restriction will be removed. &lt;/P&gt;

&lt;P&gt;You can use a more specific table, or any aggregating command to get the same result.,This has to do with the difference between "events" and "results." For performance, splunk will only pull the first 1000 events back to the SH, but this restriction does not apply to results.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2014 17:46:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132877#M36281</guid>
      <dc:creator>jacobwilkins</dc:creator>
      <dc:date>2014-10-15T17:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search limits results to 1000 events only</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132878#M36282</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;I think that this search code will help 
 error OR failed OR severe OR ( sourcetype=access_* ( 404 OR 500 OR 503 ) ) earliest=-24h@h 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 16 Mar 2015 08:58:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132878#M36282</guid>
      <dc:creator>chimell</dc:creator>
      <dc:date>2015-03-16T08:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search limits results to 1000 events only</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132879#M36283</link>
      <description>&lt;P&gt;Thank you. This post helped me solve a long overdue problem. Points awarded!&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2015 19:35:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-limits-results-to-1000-events-only/m-p/132879#M36283</guid>
      <dc:creator>karan1337</dc:creator>
      <dc:date>2015-07-03T19:35:42Z</dc:date>
    </item>
  </channel>
</rss>

