I have tried increase max_result by referring to
https://answers.splunk.com/answers/542862/how-to-overcome-csv-max-results-to-email.html
However, when I do ad-hoc search sending out email, the results are still limited at 50000 events:
sourcetype=foo | sendemail to=foo@foo.com sendcsv=true subject="more than 50000 events"
What else should I do to increase the limit?
The limit is defined in command.conf.
However, you can either increase this value by assigning maxinputs
sourcetype=foo | sendemail to=foo@foo.com sendcsv=true subject="more than 50000 events" maxinputs=500000
OR
permanently increase default maxinputs value in command.conf:
# maximum data that can be passed to command (0 = no limit)
maxinputs = 500000
The limit is defined in command.conf.
However, you can either increase this value by assigning maxinputs
sourcetype=foo | sendemail to=foo@foo.com sendcsv=true subject="more than 50000 events" maxinputs=500000
OR
permanently increase default maxinputs value in command.conf:
# maximum data that can be passed to command (0 = no limit)
maxinputs = 500000