Getting Data In

After upgrading to 5.0.3, I can only export 100 lines of csv via UI.

the_wolverine
Champion

Upgraded from 4.3.x to 5.0.3 this week and noticed that exporting from UI only produces 100 lines of CSV. Yes, I checked "Unlimited" and even tried checking the 10000 lines option.

Using * | outputcsv myfile.csv produces a csv file with the correct number of lines (more than 100).

0 Karma

bfernandez
Communicator

It is not taking the maxout configuration that is 100 events in a search query by defafult.
Try this CLI example:

Without maxout:

./splunk search "| savedsearch name" -output csv > /data/test/export.csv

(in jobs view) | savedsearch Datos_Grupo_9 | head 100 | export add_timestamp=f add_offset=t format=csv segmentation=raw

With maxout:
./splunk search "| savedsearch name" -output csv -maxout 0 > /data/test/export.csv

(in jobs view) | savedsearch Datos_Grupo_9 | export add_timestamp=f add_offset=t format=csv segmentation=raw

0 Karma

the_wolverine
Champion

So the setting that we used in version 4.3.x did not affect EXPORT but it does in version 5.0?

0 Karma

Chubbybunny
Splunk Employee
Splunk Employee

limits.conf

  [restapi]
    # maximum result rows to be returned by /events or /results getters from REST API  
    maxresultrows = 50000

you'll need to increase that, enjoy!

(\__/)
(='.'=)
(")_(")
*shout-out to Rob C. too!

Rob
Splunk Employee
Splunk Employee

Thx Chubbybunny

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...