Getting Data In

Why do I have a different result in a saved search from CSV files and a different saved search history?

ifbeli
New Member

Hi guys,

We have a saved search that takes its sources from 5 csv files. On a run, it returns back 10k of events.

However, when I have a look at the saved search history, the number of events is not 10k and the source csv file for the current day is not there, meaning that we have 4 csv files as sources.

May be I am missing something, but is that a default behavior or something that we could change here ?

Let me know if you need more information.

Regards,

Iliya

0 Karma

micahkemp
Champion

How is your search taking data from the CSV files? Are they indexed files, or are you using | inputlookup or something else?

0 Karma

ifbeli
New Member

They are indexed files.

0 Karma

valiquet
Contributor

Maybe you reached numb. of results in limits.conf
Maybe check if it's shared globally

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...