We have a saved search that takes its sources from 5 csv files. On a run, it returns back 10k of events.
However, when I have a look at the saved search history, the number of events is not 10k and the source csv file for the current day is not there, meaning that we have 4 csv files as sources.
May be I am missing something, but is that a default behavior or something that we could change here ?
Let me know if you need more information.
How is your search taking data from the CSV files? Are they indexed files, or are you using
| inputlookup or something else?
Maybe you reached numb. of results in limits.conf
Maybe check if it's shared globally