Knowledge Management

Eventtypes' numbers limits

nik_splunk
Path Finder

Good Morning all,

Anybody knows if exists a limit regarding the amount of eventtype I could set into splunk? I already started to create eventtypes and corresponding tags for a Splunk's installation over a very large IT enviroment (also multiplatform), assuming there are no restriction. In case of limitations...is there a workaround to get my goal?

Thanks in advance for your time.

Nik

Tags (3)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

There is no hard limit, but it is probably a bad idea to have more than a few hundred as it will impact search speed. You might consider using lookup tables on data instead. These should scale to several hundred thousand or a few million entries without any trouble.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

There is no hard limit, but it is probably a bad idea to have more than a few hundred as it will impact search speed. You might consider using lookup tables on data instead. These should scale to several hundred thousand or a few million entries without any trouble.

nik_splunk
Path Finder

Thank you gkanapathy, for your support and you precious suggestion. Have a good time!

nik

0 Karma

harshsarode1234
New Member

how to get only 100 recent event logs.Thanks in advance.

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...