Installation

Report not exporting all events

snigdhasaxena
Communicator

When search query for report is run in Splunk, it shows 15000 events for last 7 days (example 4/14-4/21) but when I export results in csv, it exports events only for 4/21.
I have reset dispatch.max_count to 0 but still it doesn't retrieve all events in csv when report runs.

Tags (1)
0 Karma

manjunathmeti
Champion

Go to Settings >> Searches, Reports, and Alerts.

Find and click on report name and check Earliest time and Latest time. Set these if not set directly the query.

0 Karma

snigdhasaxena
Communicator

I tried but still not all events are exported in csv

0 Karma

manjunathmeti
Champion

How are you exporting? Is it some alert action?

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...