Installation

Report not exporting all events

snigdhasaxena
Communicator

When search query for report is run in Splunk, it shows 15000 events for last 7 days (example 4/14-4/21) but when I export results in csv, it exports events only for 4/21.
I have reset dispatch.max_count to 0 but still it doesn't retrieve all events in csv when report runs.

Tags (1)
0 Karma

manjunathmeti
Champion

Go to Settings >> Searches, Reports, and Alerts.

Find and click on report name and check Earliest time and Latest time. Set these if not set directly the query.

0 Karma

snigdhasaxena
Communicator

I tried but still not all events are exported in csv

0 Karma

manjunathmeti
Champion

How are you exporting? Is it some alert action?

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...