All Apps and Add-ons

Too many results returned

araitz
Splunk Employee
Splunk Employee

dmlee asks:

Hi,

thanks for your great App, I do a test using ver 1.3.1 and find a problem, for example I search 10,000 rows : source="/opt/apache/log/access_combined.log"| head 10000 | table action, bytes, clientip

and I use ExportExcel module to export above result set, but I got 13,740 rows in excel ! I tried to search and export 1,000 rows , I will get correct results.

I don't know why.

Regards,

Owen

1 Solution

araitz
Splunk Employee
Splunk Employee

I am currently working on version 2.0, the road map for which is listed here: http://splunk-base.splunk.com/apps/29336/splunk-for-excel-export. I have reproduced a few cases where too many results were returned, or where multiline exports had partial _raw fields. I am working on fixing these issues for 2.0 as well.

EDIT: Version 2.0 was released on May 13th and includes several performance and stability improvements.

View solution in original post

araitz
Splunk Employee
Splunk Employee

I am currently working on version 2.0, the road map for which is listed here: http://splunk-base.splunk.com/apps/29336/splunk-for-excel-export. I have reproduced a few cases where too many results were returned, or where multiline exports had partial _raw fields. I am working on fixing these issues for 2.0 as well.

EDIT: Version 2.0 was released on May 13th and includes several performance and stability improvements.

Takajian
Builder

Addition to previous my comment, I used browser Google Chrome 17, Firefox 9, IE 9. Splunk OS is 4.3.1. I see this issue with any type of data. The platform is linux. Do you have any idea to solve the issue?

0 Karma

Takajian
Builder

In my case, I used chart and stats command. The result was 10 rows, but I exported over 100 rows with excel. The search command is like "sourcetype=xxxx | chart count by yyyy" or "sourcetype=xxxx | stats count by yyyy". I assume this issue can be reproduce on other splunk instances. If you need more info to reproduce the issue in your environment, please let me know.

0 Karma

araitz
Splunk Employee
Splunk Employee

I am working on reproducing the issues. Any additional information that you can provide with regard to the type of data and your browser and Splunk OS version would be awesome.

0 Karma

Takajian
Builder

I faced the same issue. The ExportExcel module exports incorrect search results. I hope this issue will be fixed soon.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...