Same issue here.... 18,000 events, only 1,000 returned using loadjob.
If you append a table command with the field list you are interested in it may work around your issue.
To verify your suggestion, I tried this but can not repeat my issue again.
|loadjob SID events=t
It returned more than 1000 events. Splunk version 6.4
I forgot why I used "load" and "pid", and what I searched 3 years ago.
Any one have the same issue, could you plz post your search conditions?
The issue was likely fixed in a more recent version of splunk. The table command was just a workaround because it transforms event data into results data and thus worked around the bug in loading all of the events data.
has anyone figured this out since 2013?
Hi,
Was this question answered? I am looking at a similar problem.
Thanks
Same problem, even with DalJeanis's suggestion... Any fix?
|loadjob SID events=t
Hi Eva,
I'm having the same issue. Did you get this resolved?
Steve