Reporting

outputcsv limiting outputs to 10,000 rows

gordo32
Communicator

Running Splunk 6.6.4 on Ubuntu, and piping query results (25,000+ rows) to " | outputcsv filename.csv", but the output is consistently limited to 10,000 rows + header row (e.g. "grep -c . filename.csv" returns 10001).

According to documentation, there is no output limit to outputcsv. I can't find anything in limits.conf that seems applicable either.

Am I doing something wrong?

0 Karma

gordo32
Communicator

Nevermind. I didn't realize there was a Job alert indicating that "sort is limiting search results to 10000". Removing the |sort from my query resolved the issue.

0 Karma

493669
Super Champion

are you using sort command if yes then use like:

...|sort limit=0

As outputcsv does not have any results limits

493669
Super Champion

instead of removing sort you can use it with limit=0 which will not limit your data..

..|sort 0 <fieldname>
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...