Getting Data In

How can I increase the output count limit for the command.script component?

ctaf
Contributor

Hi,

I have a search that is using the "script" command but this search is exceeding a limit as you can see:
here

Is there a way to increase this limit?
I tried maxinputs of the commands.conf file but without any luck.

Any guess?
Thank you.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi ctaf,
could you share your search? because maybe the problem is in another parameter (e.g. sort is limited to 10k events) and there are other parameters to set (e.g. maxresultrows or maxresultrows or subsearch_maxout in join, etc...) in limits.conf.
Bye.
Giuseppe

0 Karma

ctaf
Contributor

It's quite simple:

 search index=XXX | table XXXX  | stats XXX | lookup XXX | script python YYYY arg 

There is no join or sort...

I saw maxresultrows but there is no "script" stanza...

0 Karma

gcusello
SplunkTrust
SplunkTrust

if you don't use script command, have you always the same limit?
in addition, you don't need to use the table command before a stats command (it only reduces speed of your search).
Bye.
Giuseppe

0 Karma

ctaf
Contributor

There is no command.script component if I don't use it...

0 Karma

gcusello
SplunkTrust
SplunkTrust

Have you seen the limits in command.conf file for your script use?
There are:

maxinputs = <integer>
* Maximum number of events that can be passed to the command for each
  invocation.
* This limit cannot exceed the value of maxresultrows in limits.conf.
* 0 for no limit.
* Defaults to 50000.

.

maximum data that can be passed to command (0 = no limit)
MAXINPUTS = 50000

Bye.
Giuseppe

0 Karma

ctaf
Contributor

Giuseppe,

As I wrote on my original post, I already tried it.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...