Reporting

When creating an alert that creates a .csv file to be emailed , the .csv contains 9000 with an error.

SamHTexas
Builder

When creating an alert that creates a .csv file to be emailed , the .csv contains 9000 with an error that only the first 9000 of the 40,000 results are included. Please advise.

Labels (1)
Tags (1)
0 Karma
1 Solution

s2_splunk
Splunk Employee
Splunk Employee

There is a setting in the alerting search (savedsearches.conf) called 

action.email.maxresults

The default is 10000, not sure why you are getting 9000, maybe it was overwritten. 

But that's where I would look first.

View solution in original post

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

There is a setting in the alerting search (savedsearches.conf) called 

action.email.maxresults

The default is 10000, not sure why you are getting 9000, maybe it was overwritten. 

But that's where I would look first.

0 Karma

SamHTexas
Builder

Please tell me where do I find this savedsearches.conf file. Which server is it on?

Tags (1)
0 Karma

s2_splunk
Splunk Employee
Splunk Employee

(Saved) searches are initiated on the Search Head;  you should find it there.

You can also see the settings in effect in the UI under Settings->Searches, reports, and alerts if you select "Advanced Edit" from the dropdown for the relevant alerting search:

Screen Shot 2021-04-29 at 5.54.21 PM.png

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...