Reporting

How can I export more than 10000 results from the Splunk UI?

the_wolverine
Champion

It looks like there is a hard cap (10000 lines) when exporting via SplunkWeb. How, then, do I export more than 10000 lines? I really need this.

Tags (2)
1 Solution

hexx
Splunk Employee
Splunk Employee

As of Splunk 4.3, you can now export an unlimited number of events from the UI. Do note, however, that exporting too many events in that manner (typically, several millions) could cause Splunkweb to misbehave and possibly to become temporarily unresponsive.

If you really need to often export large number of events, we would still recommend the use of the outputcsv command and/or to run the search from the CLI.

View solution in original post

hexx
Splunk Employee
Splunk Employee

As of Splunk 4.3, you can now export an unlimited number of events from the UI. Do note, however, that exporting too many events in that manner (typically, several millions) could cause Splunkweb to misbehave and possibly to become temporarily unresponsive.

If you really need to often export large number of events, we would still recommend the use of the outputcsv command and/or to run the search from the CLI.

hexx
Splunk Employee
Splunk Employee

@bob999 : The csv row limit for the email alert action is indeed completely unrelated to the csv export row limit in the flashtimeline which is discussed here. I believe that the limits.conf setting that you found is pertinent to your problem, although action.email.maxresults in savedsearches.conf is probably more so.

0 Karma

r999
Path Finder

Hexx, Pease can you confirm this is fixed in 4.3? i have a scheduled saved search which emails results with CSV of results as its alert action. it seems to be truncating at 10000 rows.

This one comment by you is the only mention that this has been changed in 4.3, however i am running 4.3.1 and am still having the issue!

Could this be the reason?

limits.conf
[scheduler]
max_action_results =
* The maximum number of results to load when triggering >an alert action.
* Defaults to 10000

?

0 Karma

araitz
Splunk Employee
Splunk Employee

Splunk for Excel Export will allow you to export more than 10K results:

http://apps.splunk.com/app/760/

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...