Reporting

max search length

kondou
Explorer

Is there any limitation of search length? I've made almost 5000 bytes search commands in Splunk > Search, tried to save it, but met an error;

500 Internal Server Error XMLSyntaxError: Start tag expected, '<' not found, line 1, column 1

Is there any way to avoid this other than not changing search command.

Tags (1)

jrodman
Splunk Employee
Splunk Employee

splunkd has some failure modes I'm sure for searches above some size, even if just performance issues or ungainly handling, but several hundred kilobyte searches work just fine.

The problem you're seeing is happening in splunkweb. I suspect it's some kind of quoting failure, rather than a length issue. If the exact string isn't sensitive, I'd love to reproduce and file the bug. A support ticket would be appropriate.

As a lame workaround, manually adding the search to a savedsearches.conf file will likely bypass the problem.

kondou
Explorer

Yes, the problem always happens in splunk web. I think you should be able to reproduce by creating over 5000 bytes search.

And, my workaround is almost the same as what you are saying. I just new entry in create search and report, which includes the search line, also with non error search entry. I call non search
entry from search and report tab, and then paste THAT error search, which gives me what I want.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...