All Apps and Add-ons

Too many results returned

araitz
Splunk Employee
Splunk Employee

dmlee asks:

Hi,

thanks for your great App, I do a test using ver 1.3.1 and find a problem, for example I search 10,000 rows : source="/opt/apache/log/access_combined.log"| head 10000 | table action, bytes, clientip

and I use ExportExcel module to export above result set, but I got 13,740 rows in excel ! I tried to search and export 1,000 rows , I will get correct results.

I don't know why.

Regards,

Owen

1 Solution

araitz
Splunk Employee
Splunk Employee

I am currently working on version 2.0, the road map for which is listed here: http://splunk-base.splunk.com/apps/29336/splunk-for-excel-export. I have reproduced a few cases where too many results were returned, or where multiline exports had partial _raw fields. I am working on fixing these issues for 2.0 as well.

EDIT: Version 2.0 was released on May 13th and includes several performance and stability improvements.

View solution in original post

araitz
Splunk Employee
Splunk Employee

I am currently working on version 2.0, the road map for which is listed here: http://splunk-base.splunk.com/apps/29336/splunk-for-excel-export. I have reproduced a few cases where too many results were returned, or where multiline exports had partial _raw fields. I am working on fixing these issues for 2.0 as well.

EDIT: Version 2.0 was released on May 13th and includes several performance and stability improvements.

Takajian
Builder

Addition to previous my comment, I used browser Google Chrome 17, Firefox 9, IE 9. Splunk OS is 4.3.1. I see this issue with any type of data. The platform is linux. Do you have any idea to solve the issue?

0 Karma

Takajian
Builder

In my case, I used chart and stats command. The result was 10 rows, but I exported over 100 rows with excel. The search command is like "sourcetype=xxxx | chart count by yyyy" or "sourcetype=xxxx | stats count by yyyy". I assume this issue can be reproduce on other splunk instances. If you need more info to reproduce the issue in your environment, please let me know.

0 Karma

araitz
Splunk Employee
Splunk Employee

I am working on reproducing the issues. Any additional information that you can provide with regard to the type of data and your browser and Splunk OS version would be awesome.

0 Karma

Takajian
Builder

I faced the same issue. The ExportExcel module exports incorrect search results. I hope this issue will be fixed soon.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...