Knowledge Management

Is there a limit to how many tags can be defined in Splunk 6.3.1?

abhijitp
Path Finder

Hi,

I have around 100 test units in Splunk. I started off with creating tags for them to describe and quickly categorize them.

Eg. 1Camera, 2Camera, 3Camera and 4Camera. I first created these tags and they worked fine. 2Camera is the bulk of them, around 80 units. I am tagging them based on the Serial Number.

Field Value pair is -> SerialNumber=abcd1234
Tag name is -> 2Camera

Then carrying forward this concept, I created another category of tags with a different variable like Transport mode - Wireless or Cellular based on the same Serial Number.

Field Value pair is -> SerialNumber=abcd1234
Tag name is -> Wireless

In this, the original tags for 2Camera system "disappear" from the Splunk tags. I have re-created them more than 10 times, but they just disappear. I input the 80 units and they do not get updated in Splunk. I have also tried 10 at a time, but when I change the permissions so that everyone can see them, they disappear after around 20.

I now have a very tough time re-creating the original tags for 2Camera systems. I am noticing that these tags disappear after say 20 of them have been re-created.

  1. Is there a limit as to how many tags can be defined in Splunk? For some reason, I am thinking it is 20. I was not able to confirm it.
  2. Is there a limit on how multiple tags can be defined in Splunk actively?

Please help.

Thanks a lot,
Abhi

0 Karma
1 Solution

muebel
SplunkTrust
SplunkTrust

Hi abhijitp, The documentation in this case states that you can "set any number of tags" http://docs.splunk.com/Documentation/Splunk/6.3.3/Admin/Tagsconf

So I'd hope that you aren't running into a limit. It is strange that you are seeing this config disappear however. My advice would be to identify the tags.conf file on the filesystem, and make the changes there. In that way, you can be very certain that all the config is in place, and if any goes missing then I would expect you have a strange bug or something, and would probably need to reach out to Splunk Support.

Please let me know if this helps!

View solution in original post

muebel
SplunkTrust
SplunkTrust

Hi abhijitp, The documentation in this case states that you can "set any number of tags" http://docs.splunk.com/Documentation/Splunk/6.3.3/Admin/Tagsconf

So I'd hope that you aren't running into a limit. It is strange that you are seeing this config disappear however. My advice would be to identify the tags.conf file on the filesystem, and make the changes there. In that way, you can be very certain that all the config is in place, and if any goes missing then I would expect you have a strange bug or something, and would probably need to reach out to Splunk Support.

Please let me know if this helps!

abhijitp
Path Finder

Thanks muebel. Let me try this out. I will report back my findings shortly.

0 Karma

abhijitp
Path Finder

Thanks muebel. I just tried this out on our production system and it worked exactly as expected.

Thanks.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...