Security

Notable action "for each result" limits to 250 (or 500)- How do I see all?

rookiemonster
Splunk Employee
Splunk Employee

When I generate notable "for each result" the max number of notables is 250 or 500

I want all results to produce an notable

0 Karma
1 Solution

rookiemonster
Splunk Employee
Splunk Employee

max_per_result_alerts

On prem: https://docs.splunk.com/Documentation/Splunk/latest/Admin/Limitsconf

max_per_result_alerts = <integer>
* Maximum number of alerts to trigger for each saved search instance (or
  real-time results preview for RT alerts)
* Only applies in non-digest mode alerting. Use 0 to disable this limit
* Default: 500

 

Cloud: https://docs.splunk.com/Documentation/SplunkCloud/9.0.2209/Config/ManageLimits

max_per_result_alertsMaximum number of alerts to trigger for each saved search instance (or real-time results preview for RT alerts). Only applies in non-digest mode alerting."minValue": 250

"maxValue": 5000
"defaultValue": 500

 

 

lrh

View solution in original post

0 Karma

rookiemonster
Splunk Employee
Splunk Employee

max_per_result_alerts

On prem: https://docs.splunk.com/Documentation/Splunk/latest/Admin/Limitsconf

max_per_result_alerts = <integer>
* Maximum number of alerts to trigger for each saved search instance (or
  real-time results preview for RT alerts)
* Only applies in non-digest mode alerting. Use 0 to disable this limit
* Default: 500

 

Cloud: https://docs.splunk.com/Documentation/SplunkCloud/9.0.2209/Config/ManageLimits

max_per_result_alertsMaximum number of alerts to trigger for each saved search instance (or real-time results preview for RT alerts). Only applies in non-digest mode alerting."minValue": 250

"maxValue": 5000
"defaultValue": 500

 

 

lrh

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...