Knowledge Management

Eventtypes' numbers limits

nik_splunk
Path Finder

Good Morning all,

Anybody knows if exists a limit regarding the amount of eventtype I could set into splunk? I already started to create eventtypes and corresponding tags for a Splunk's installation over a very large IT enviroment (also multiplatform), assuming there are no restriction. In case of limitations...is there a workaround to get my goal?

Thanks in advance for your time.

Nik

Tags (3)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

There is no hard limit, but it is probably a bad idea to have more than a few hundred as it will impact search speed. You might consider using lookup tables on data instead. These should scale to several hundred thousand or a few million entries without any trouble.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

There is no hard limit, but it is probably a bad idea to have more than a few hundred as it will impact search speed. You might consider using lookup tables on data instead. These should scale to several hundred thousand or a few million entries without any trouble.

nik_splunk
Path Finder

Thank you gkanapathy, for your support and you precious suggestion. Have a good time!

nik

0 Karma

harshsarode1234
New Member

how to get only 100 recent event logs.Thanks in advance.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...