The dbxoutput command has a row limit of 50k rows, where can I increase this threshold?
By default Splunk displays 100000 rows. To override this and display all the rows, add the parameter maxrows=10000000
(or any lower number) in the dbxquery along with the connection and query parameters.
PLEASE NOTE : It is not always suggested as a best practice to increase or override the limit as it would result in consuming more space and thereby slowing down the searching performance.
FYR - https://docs.splunk.com/Documentation/DBX/latest/DeployDBX/Commands
I had this same problem recently and with some digging found the following in limits.conf
[searchresults]
maxresultrows = <integer>
* Configures the maximum number of events are generated by search commands which grow the size of your result set (such as multikv) or that create events. Other search commands are explicitly controlled in specific stanzas below.
* This limit should not exceed 50000. Setting this limit higher than 50000 causes instability.
* Defaults to 50000.
Setting this higher resolved the issue.