Reporting

max search length

kondou
Explorer

Is there any limitation of search length? I've made almost 5000 bytes search commands in Splunk > Search, tried to save it, but met an error;

500 Internal Server Error XMLSyntaxError: Start tag expected, '<' not found, line 1, column 1

Is there any way to avoid this other than not changing search command.

Tags (1)

jrodman
Splunk Employee
Splunk Employee

splunkd has some failure modes I'm sure for searches above some size, even if just performance issues or ungainly handling, but several hundred kilobyte searches work just fine.

The problem you're seeing is happening in splunkweb. I suspect it's some kind of quoting failure, rather than a length issue. If the exact string isn't sensitive, I'd love to reproduce and file the bug. A support ticket would be appropriate.

As a lame workaround, manually adding the search to a savedsearches.conf file will likely bypass the problem.

kondou
Explorer

Yes, the problem always happens in splunk web. I think you should be able to reproduce by creating over 5000 bytes search.

And, my workaround is almost the same as what you are saying. I just new entry in create search and report, which includes the search line, also with non error search entry. I call non search
entry from search and report tab, and then paste THAT error search, which gives me what I want.

0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...