Splunk Search

After running a top 10 search, is it possible to increase how many results are displayed in the left navigation?

bbazian
New Member

Can I increase the display of results on the left nav after a search from the top 10? For example, when I do a search, it shows that there are 19 hosts, but I can only see the top 10. I would like to be able to see all of them.

0 Karma

somesoni2
Revered Legend

The number of top values shown, for each field is not configurable. There is a workaround but it's not recommended as it involves updating core code of Splunk and any upgrade of Splunk will overwrite it.

To expand on the above for the less experienced - if you wish to increase the number of results shown when you click on a field you need to edit this file:

{splunk install}/share/splunk/search_mrsparkle/modules/results/SuggestedFieldViewer.conf

and add a stansa:

[param:count]
required = False
default = 20

As that this is not a documented feature of the product it's also probably liable to change in future releases without notice. The value of your investment could go up as well as down.

0 Karma

JoshuaJohn
Contributor
search query | top limit=20 host

This will show you the top 20 hosts
...

Realized this is not what you asked check this:
https://answers.splunk.com/answers/7298/increase-top-10-field-values-in-search-app-increase-limits-o...

0 Karma

bbazian
New Member

Thanks for the reply but that does not really accomplish what I am looking for. I would like all of the items under the "selected fields" on the left nav to show all items when I click on it, not just the top 10. Is there no global setting there? How do I get to see the other hosts in that dialog when I click on "hosts" for example?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...