Reporting

Export limit in 5.x

tawollen
Path Finder

I have a 2 search heads distributed to the same servers. I run a search: index=X sourcetype=Y | table A B C

The search completes with 317,000 results.

On 4.3.4 when I do an "unlimited" export (to CSV) I get all 317,000 results
5.0.2 only 50,000 results in the "unlimited" export.

Is there a new limit to "unlimited"?

Tags (1)

Ron_Naken
Splunk Employee
Splunk Employee

The configuration option that should affect the number of results exported for a table is this:

LIMITS.CONF:
[restapi]
maxresultrows = 50000

Increase that value to the desired maximum number of events. It doesn't look as if this limit has changed between version 4.3.4 and 5.x, so maybe you had configured the value in /default and the upgrade overwrote the changes. Be sure to save your configuration changes in a /local folder. Don't forget to restart Splunk after making the change.

As a side note, if you export the events without "| table", you should receive a full list without the option set.

ben_leung
Builder

Is there a bug in this configuration?

Set maxresultrows = 100, exported results as csv file, set to unlimited, gave all results.

Is this the wrong configuration to look at when limiting the returned results from UI export button?

0 Karma

alancalvitti
Path Finder

@Ron Naken , is it possible for users to override maxresultrows in Enterprise version?

0 Karma

ben_leung
Builder

version 6.0.5

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...