When I generate notable "for each result" the max number of notables is 250 or 500
I want all results to produce an notable
max_per_result_alerts
On prem: https://docs.splunk.com/Documentation/Splunk/latest/Admin/Limitsconf
max_per_result_alerts = <integer> * Maximum number of alerts to trigger for each saved search instance (or real-time results preview for RT alerts) * Only applies in non-digest mode alerting. Use 0 to disable this limit * Default: 500
Cloud: https://docs.splunk.com/Documentation/SplunkCloud/9.0.2209/Config/ManageLimits
max_per_result_alerts | Maximum number of alerts to trigger for each saved search instance (or real-time results preview for RT alerts). Only applies in non-digest mode alerting. | "minValue": 250 "maxValue": 5000 |
lrh
max_per_result_alerts
On prem: https://docs.splunk.com/Documentation/Splunk/latest/Admin/Limitsconf
max_per_result_alerts = <integer> * Maximum number of alerts to trigger for each saved search instance (or real-time results preview for RT alerts) * Only applies in non-digest mode alerting. Use 0 to disable this limit * Default: 500
Cloud: https://docs.splunk.com/Documentation/SplunkCloud/9.0.2209/Config/ManageLimits
max_per_result_alerts | Maximum number of alerts to trigger for each saved search instance (or real-time results preview for RT alerts). Only applies in non-digest mode alerting. | "minValue": 250 "maxValue": 5000 |
lrh