Splunk Enterprise

Receiving error while using mvexpand

super_saiyan
Communicator

While using the mvexpand command, i am getting the below error.

ERROR - 

command.mvexpand: output will be truncated at 1000 results due to excessive memory usage. Memory threshold of 500 MB as configured in limits.conf /[mvexpand]/max_mem_usage_mb has been reached.

 

Question 1- How can i resolve the above error ?

Question 2 -  Is there any other alternative command of mvexpand ?

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

mvexpand functionality can be replicated to some extent using makecontinuous

https://community.splunk.com/t5/Splunk-Enterprise/Mutlivalue-Field-Problem-Is-there-any-way-to-do-th...

However, you may still run into memory issues.

The memory issue can be postponed by configuring more memory in limits.conf

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

You can raise the limits of course to delay the onset of the problem a little, as others already mention. But the question is why do you have such a big mvexpand. If you're mvexpanding original events, maybe it's worth reviewing onboarding of this sourcetype. If it's because you did some huge "stats values" or something similar, maybe you should review your search and try to get to the results another way.

ITWhisperer
SplunkTrust
SplunkTrust

mvexpand functionality can be replicated to some extent using makecontinuous

https://community.splunk.com/t5/Splunk-Enterprise/Mutlivalue-Field-Problem-Is-there-any-way-to-do-th...

However, you may still run into memory issues.

The memory issue can be postponed by configuring more memory in limits.conf

VatsalJagani
SplunkTrust
SplunkTrust

@super_saiyan - Generally you should look at the option of changing your query in such a way that you do not require to use mvexpand. (Avoid multi-valued fields where you expect to have more than 1000 values.)

If not possible, then you can look at the option provided by @ITWhisperer 

 

I hope this helps!!!

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Data Drivers: How We're Streaming Real-Time F1 Telemetry Directly into Splunk ...

Data Drivers: Every Lap Tells a Story The Spectacle Two F1 racing sims go head-to-head on the .conf26 show ...

Data Management Digest – July 2026

  Welcome to the July 2026 edition of Data Management Digest! As your trusted partner in data innovation, the ...