Hi to all,
I am a real newbie in Splunk. Sorry for my simple question, but I really need help.
I have set an automated alert on Splunk that collects over 8000 results when triggered. I tried dispatch those results by email in a .csv document, but Splunk only attach first 1000 results to the file. Vice versa when I relaunched the search manually, it made easily a complete csv document.
How I can extend the number of results in mail attachment ?
I also read the topic Splunk Alert only includes first 1000 results of search. Why? but it seems to me does not gave a solution to this problem: (there seems to be some hard-coded voodoo going on behind the scenes. And for whatever reason, that voodoo wants to keep your from sending more than 1,000 events in your email)
thanks in advance for every tip
the limits are in 2 places :
you can redefine this in our local/alert_actions.conf
Here is a way to bump the limit to 50000 for the email alerts only. (on 6.2.0, please adapt the command to your version)
[email]
command = $action.email.preprocess_results{default=""}$ | sendemail "results_link=$results.url$" "ssname=$name$" "graceful=$graceful{default=True}$" "trigger_time=$trigger_time$" maxinputs="$action.email.maxresults{default=50000}$" maxtime="$action.email.maxtime{default=5m}$" results_file="$results.file$"
maxresults=50000
Hi mekamundia,
you can apply some anti-voodoo globally in alert_actions.conf
by setting
[default]
maxinputs = <YourNewMaxResultNumber>
or per saved search/ alert in savedsearch.conf
like this:
action.email.maxinputs = <YourNewMaxResultNumber>
Hope this helps to fight the Voodoo 😉
cheers, MuS
Nothing to do.... again.
Sorry somesoni2 but also your solution does not work.
I wait for new tips from everybody.
I have tested the modify...
nothing new happened. The vodoo remains... 😞
Try maxresults attribute in alert_actions.conf and action.email.maxresults in savedsearches.conf for your search
Ok, I'll try again modifying [default] stanza.
The search runs at night: tomorrow i'llsee the results.
Thanks for your support !
Hi MuS
Yesterday I have applied the modify to alert_actions. conf and restarted the search head (where the search is saved and runs).
But the wodoo remains :(...
What i missed?
I need some more tips !
cheers,
Mekamundia
uuppsss, looks like the maxinputs belongs to the [default]
stanza and not the [email]
in alert_actions.conf
- sorry my bad
Did you try the action.email.maxinputs
in savedsearch.conf
as well?