<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to increase truncation limit to display all results in a chart? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196348#M56624</link>
    <description>&lt;P&gt;I tried the XML option but it didn't seem to work either. I also tried adjusting the limits.conf as suggested above. Restarted Splunk Web between modifications as well. Any other suggestions?&lt;/P&gt;</description>
    <pubDate>Wed, 27 Aug 2014 19:45:48 GMT</pubDate>
    <dc:creator>lbogle</dc:creator>
    <dc:date>2014-08-27T19:45:48Z</dc:date>
    <item>
      <title>How to increase truncation limit to display all results in a chart?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196343#M56619</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;

&lt;P&gt;These results may be truncated. This visualization is configured to display a maximum of 1000 results per series, and that limit has been reached.&lt;/P&gt;

&lt;P&gt;I am doing asset counts for the enterprise and am using charting to demonstrate them for high level reporting purposes. I see that my numbers appears to be coming out correctly within the Search "Events" tab details but trying to get visualization is difficult because I keep running into this limit. How do I increase it? I see some older references about XML or maybe a .conf file but nothing definite.&lt;/P&gt;

&lt;P&gt;Any suggestions?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2014 04:11:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196343#M56619</guid>
      <dc:creator>lbogle</dc:creator>
      <dc:date>2014-08-27T04:11:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to increase truncation limit to display all results in a chart?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196344#M56620</link>
      <description>&lt;P&gt;See this&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/73745/max-data-points-that-charts-can-handle"&gt;http://answers.splunk.com/answers/73745/max-data-points-that-charts-can-handle&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2014 04:33:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196344#M56620</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-08-27T04:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to increase truncation limit to display all results in a chart?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196345#M56621</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;I think you can change the setting in etc/system/default/limits.conf &lt;/P&gt;

&lt;P&gt;If you look at this: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/admin/Limitsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/admin/Limitsconf&lt;/A&gt; it apears as though the setting you would want is "truncate_report".&lt;/P&gt;

&lt;P&gt;Copy file to local, edit, and restart splunk.&lt;/P&gt;

&lt;P&gt;Regards&lt;BR /&gt;
Derek&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2014 08:47:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196345#M56621</guid>
      <dc:creator>DerekKing</dc:creator>
      <dc:date>2014-08-27T08:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to increase truncation limit to display all results in a chart?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196346#M56622</link>
      <description>&lt;P&gt;Hi @lbogle&lt;/P&gt;

&lt;P&gt;By default, chart results are truncated to 1000 as you've seen, but you can edit the limit by making a change to the charting.data.count value in simple XML. It's explained in the sub section of this documentation:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartDisplayissues#Search_result_truncation"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartDisplayissues#Search_result_truncation&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can change the value to whatever fits your needs, or you can set it to 0 to get all results as referenced here: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartConfigurationReference#General_chart_properties"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartConfigurationReference#General_chart_properties&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this solves your issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Patrick&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2014 17:44:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196346#M56622</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2014-08-27T17:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to increase truncation limit to display all results in a chart?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196347#M56623</link>
      <description>&lt;P&gt;Hi Patrick. Tried the web.conf fix but no go. Will try XML and get back to you.&lt;BR /&gt;
Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2014 18:10:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196347#M56623</guid>
      <dc:creator>lbogle</dc:creator>
      <dc:date>2014-08-27T18:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to increase truncation limit to display all results in a chart?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196348#M56624</link>
      <description>&lt;P&gt;I tried the XML option but it didn't seem to work either. I also tried adjusting the limits.conf as suggested above. Restarted Splunk Web between modifications as well. Any other suggestions?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2014 19:45:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196348#M56624</guid>
      <dc:creator>lbogle</dc:creator>
      <dc:date>2014-08-27T19:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to increase truncation limit to display all results in a chart?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196349#M56625</link>
      <description>&lt;P&gt;Hi @lbogle&lt;/P&gt;

&lt;P&gt;Hmm...did you try editing the XML for both the charting.chart.resultTruncationLimit property (&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartDisplayissues#Configure_a_limit_on_a_per_chart_basis"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartDisplayissues#Configure_a_limit_on_a_per_chart_basis&lt;/A&gt; ) and charting.data.count property?&lt;/P&gt;

&lt;P&gt;The only other helpful documentation I could find was this example:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/AdvancedDev/AdvChartingConfig-LayoutData#Data"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/AdvancedDev/AdvChartingConfig-LayoutData#Data&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2014 23:05:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196349#M56625</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2014-08-27T23:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to increase truncation limit to display all results in a chart?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196350#M56626</link>
      <description>&lt;P&gt;charting.data.count worked for me and charting.chart.resultTruncationLimit did not work.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2016 13:54:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196350#M56626</guid>
      <dc:creator>mark_chuman</dc:creator>
      <dc:date>2016-01-28T13:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to increase truncation limit to display all results in a chart?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196351#M56627</link>
      <description>&lt;P&gt;For me, it works with splunk 6.3.3 and does not work with 6.3.0.&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2016 13:13:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196351#M56627</guid>
      <dc:creator>akazarov</dc:creator>
      <dc:date>2016-05-19T13:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to increase truncation limit to display all results in a chart?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196352#M56628</link>
      <description>&lt;P&gt;Have you opened a case with Splunk for this? This is a hard limit which we have an enhancement request ticket open, more customers requesting this to be raised should push Splunk to fix this.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 17:35:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196352#M56628</guid>
      <dc:creator>kbecker</dc:creator>
      <dc:date>2016-09-15T17:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to increase truncation limit to display all results in a chart?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196353#M56629</link>
      <description>&lt;P&gt;Have you opened a support case for this? We are trying to get Splunk to remove this limit and more customers behind this will help drive this.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Ken&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 15:13:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-increase-truncation-limit-to-display-all-results-in-a/m-p/196353#M56629</guid>
      <dc:creator>kbecker</dc:creator>
      <dc:date>2016-09-29T15:13:40Z</dc:date>
    </item>
  </channel>
</rss>

