Splunk Search

Bug? splunk advanced searching/views does not display correctly

nina15
Communicator

Hi...
Its been a while I have problems with searching in Google maps or geoip which the thread was going on here: geoip search results not correct

if u follow up the thread, u see it came to a point that we all realized there exists some sort of limit that does not let geoip or Google maps to display more than ten thousand...
today suddenly, I realized its not only geoip/Google maps, but it actually is any kind of advanced searches. for instance if you search for all the data in normal search using "*", and if you have huge number of indexed data, (i.e. billions of data), u'll probably see all in the search but if you change the view to "Advanced Charting View" then you'll only see partially few thousands of those results...
Im not sure whether this is a bug or if there is some sort of limitation in any file... but that definitely causes major problems.
Does anyone have any idea how to solve this issue..?

Tags (2)

nina15
Communicator

thanks for your response...

ok, to access the module I have to go to Manage Views, right..??
there was no such thing as maxResultCount for charting view..
i saw the width, height, even maxpages, but no max result count...

also, if that was the case, how come when I search in normal search, it gives me 5 billions of data but when I just add geoip commands to the same exact search windows, suddenly only shows 19,000 events!!?!!

to be more specific, when I search for SourceIP="" I get billions of event results, but when I search for SourceIP="" | geoip SourceIP I only get 19,000..

so for the case of advanced charting also when I search for SourceIP="*" I only get 15000 while the normal search as I said were few billions...

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...