Splunk Cloud Platform

Splunk Search Limits

masonwillinger
Explorer

All searches appear to be limited to 1000 results in the UI. Can this be modified in a configuration setting somewhere?

Screenshot of message indicating that the limit is 1000 has been attached.

Labels (1)
0 Karma

manish_singh_77
Builder

The default value of 50000 can be modified by editing the [searchresults] stanza in limits.conf:

 [searchresults]
 maxresultrows = 100000

 

Tags (1)

masonwillinger
Explorer

Thanks Manish. If the default value is 50000, then why are we seeing a limit of 1000? I don't think we've ever changed this value, mostly because we're in a managed cloud instance and don't have access to change that value. Perhaps the default is different for cloud instances?

0 Karma

manish_singh_77
Builder
0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...