Splunk Enterprise

Is the only to change the subsearch limit is to modify limits.conf?

jip31
Motivator

Hi

I have a basic question about the append limit which is 50000 events max

Does it means that only the 50000 first events sorted by timestamp are displayed (from newest to oldest)?

And in some discussions, it seems that these limit could be overrided with

 

 

 

 | sort 0 

 

 

 

https://community.splunk.com/t5/Splunk-Search/Using-sort-0-to-avoid-10000-row-limit/m-p/502707

is it true or the only way to change the limit is to modify limits.conf?

thanks

 

Labels (1)
Tags (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

sort 0 only affects the number of events in the sort, not the subsearch (which is still restricted to 50000)

You can however do multiple appends, each with a different subset of events!

0 Karma

jip31
Motivator

doest it means there is a sort events number imit if we dont use | sort 0?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...