I've built a very small example to reproduce a problem I am having. Using this page as an example:
http://www.splunk.com/base/Documentation/4.2.1/Developer/FormSearchPostProcess
I've built a dashboard that looks like this:
Post process is limited to 10,000 events. If you want the full amount you can split into unique searches.
Some values are configurable in limits.conf
Post process is limited to 10,000 events. If you want the full amount you can split into unique searches.
Some values are configurable in limits.conf
@jgauthier - He's saying instead of doing a single searchTemplate and then searchPostProcess for each chart, get rid of searchPostProcess and do a searchTemplate within each chart. It means you're going to run more searches, but ultimately will be able to surpass the 10,000 event limit.
I'm not sure I understand "split into unique searches." and how it applies to this. Could you elaborate?