Reporting

When creating an alert that creates a .csv file to be emailed , the .csv contains 9000 with an error.

SamHTexas
Builder

When creating an alert that creates a .csv file to be emailed , the .csv contains 9000 with an error that only the first 9000 of the 40,000 results are included. Please advise.

Labels (1)
Tags (1)
0 Karma
1 Solution

s2_splunk
Splunk Employee
Splunk Employee

There is a setting in the alerting search (savedsearches.conf) called 

action.email.maxresults

The default is 10000, not sure why you are getting 9000, maybe it was overwritten. 

But that's where I would look first.

View solution in original post

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

There is a setting in the alerting search (savedsearches.conf) called 

action.email.maxresults

The default is 10000, not sure why you are getting 9000, maybe it was overwritten. 

But that's where I would look first.

0 Karma

SamHTexas
Builder

Please tell me where do I find this savedsearches.conf file. Which server is it on?

Tags (1)
0 Karma

s2_splunk
Splunk Employee
Splunk Employee

(Saved) searches are initiated on the Search Head;  you should find it there.

You can also see the settings in effect in the UI under Settings->Searches, reports, and alerts if you select "Advanced Edit" from the dropdown for the relevant alerting search:

Screen Shot 2021-04-29 at 5.54.21 PM.png

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...