All Apps and Add-ons

Too many results returned

araitz
Splunk Employee
Splunk Employee

dmlee asks:

Hi,

thanks for your great App, I do a test using ver 1.3.1 and find a problem, for example I search 10,000 rows : source="/opt/apache/log/access_combined.log"| head 10000 | table action, bytes, clientip

and I use ExportExcel module to export above result set, but I got 13,740 rows in excel ! I tried to search and export 1,000 rows , I will get correct results.

I don't know why.

Regards,

Owen

1 Solution

araitz
Splunk Employee
Splunk Employee

I am currently working on version 2.0, the road map for which is listed here: http://splunk-base.splunk.com/apps/29336/splunk-for-excel-export. I have reproduced a few cases where too many results were returned, or where multiline exports had partial _raw fields. I am working on fixing these issues for 2.0 as well.

EDIT: Version 2.0 was released on May 13th and includes several performance and stability improvements.

View solution in original post

araitz
Splunk Employee
Splunk Employee

I am currently working on version 2.0, the road map for which is listed here: http://splunk-base.splunk.com/apps/29336/splunk-for-excel-export. I have reproduced a few cases where too many results were returned, or where multiline exports had partial _raw fields. I am working on fixing these issues for 2.0 as well.

EDIT: Version 2.0 was released on May 13th and includes several performance and stability improvements.

Takajian
Builder

Addition to previous my comment, I used browser Google Chrome 17, Firefox 9, IE 9. Splunk OS is 4.3.1. I see this issue with any type of data. The platform is linux. Do you have any idea to solve the issue?

0 Karma

Takajian
Builder

In my case, I used chart and stats command. The result was 10 rows, but I exported over 100 rows with excel. The search command is like "sourcetype=xxxx | chart count by yyyy" or "sourcetype=xxxx | stats count by yyyy". I assume this issue can be reproduce on other splunk instances. If you need more info to reproduce the issue in your environment, please let me know.

0 Karma

araitz
Splunk Employee
Splunk Employee

I am working on reproducing the issues. Any additional information that you can provide with regard to the type of data and your browser and Splunk OS version would be awesome.

0 Karma

Takajian
Builder

I faced the same issue. The ExportExcel module exports incorrect search results. I hope this issue will be fixed soon.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...