All Apps and Add-ons

export more than 10K events

fatbrainz
Explorer

Hi,

I was trying to export a result with more than 60K events with Excel Export module but no matter how many "Max # of results to export" I set, I always got a xls file with 10K lines. Is it possible to export 10K+ events?

By the way, is there any way I can use this great app on version 4.1?

Thanks.

1 Solution

araitz
Splunk Employee
Splunk Employee

Version 1.1 of the app allows streaming export of up to 65535 events/results, which is the current row limit per sheet in xlwt.

Update: In version 1.2, which I uploaded a few moments ago, you can export up to 1 million results, with up to 65,000 rows per sheet.

View solution in original post

araitz
Splunk Employee
Splunk Employee

Version 1.1 of the app allows streaming export of up to 65535 events/results, which is the current row limit per sheet in xlwt.

Update: In version 1.2, which I uploaded a few moments ago, you can export up to 1 million results, with up to 65,000 rows per sheet.

araitz
Splunk Employee
Splunk Employee

See my edit above regarding version 1.2

0 Karma

araitz
Splunk Employee
Splunk Employee

Yes, see my edit above - version 1.1 alleviates this issue up to 65535 results.

0 Karma

fatbrainz
Explorer

The search I was running is just events. I didn't use any transforming command and I put the ExcelExport module in flashtimeline.

I just did another test with a fresh install of version 4.2.4 with ExcelExport module. I searched with the command "index=_internal" and got 41,209 event. Then I export to excel and set "Max # of results to export" to 40,000 but I still got a excel file with 10,000 lines.

0 Karma

araitz
Splunk Employee
Splunk Employee

The app works on unix and Windows.

0 Karma

priyohw
Explorer

is it only works on *nix
or can we do it in windows/

0 Karma

fatbrainz
Explorer

Sorry, I didn't explain clear. I was asking if there is any chance to export more than 10K events with Splunk for Excel Export apps.

http://splunk-base.splunk.com/apps/29336/splunk-for-excel-export

Thanks.

0 Karma
Get Updates on the Splunk Community!

Video | Welcome Back to Smartness, Pedro

Remember Splunk Community member, Pedro Borges? If you tuned into Episode 2 of our Smartness interview series, ...

Detector Best Practices: Static Thresholds

Introduction In observability monitoring, static thresholds are used to monitor fixed, known values within ...

Expert Tips from Splunk Education, Observability in Action, Plus More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...