Splunk Search

Can't get past subsearch limit

msallman
Explorer

I seem to be stuck with the 100 result limit for a subsearch. I've changed maxout= to 10000 in limits.conf (and restarted Splunk), but still no luck. Any ideas on what else to try? We are on 4.1.2, btw.

Thanks, Mike

1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Pretty much seems like bug to me, either in product or documentation. You are actually supposed to change:

[format]
maxresults = 500

or whatever, as the default subsearch maxout is already 10000, but that doesn't work.

Update: Okay, it appears that there some missing documentation, both in the online docs and (oddly) in the in-product docs for the format command. The format command takes an option maxresults which defaults to 100 unless otherwise specified (and is separate from the limit in limits.conf. To make it apply in subsearch, you must use the format command explicitly (rather than letting it format the subsearch results implicitly, e.g. sourcetype=zzz [search xxx | fields yy | format maxresults=495 ] instead of sourcetype=zzz [search xxx | fields yy]

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

updated answer with a solution below

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Pretty much seems like bug to me, either in product or documentation. You are actually supposed to change:

[format]
maxresults = 500

or whatever, as the default subsearch maxout is already 10000, but that doesn't work.

Update: Okay, it appears that there some missing documentation, both in the online docs and (oddly) in the in-product docs for the format command. The format command takes an option maxresults which defaults to 100 unless otherwise specified (and is separate from the limit in limits.conf. To make it apply in subsearch, you must use the format command explicitly (rather than letting it format the subsearch results implicitly, e.g. sourcetype=zzz [search xxx | fields yy | format maxresults=495 ] instead of sourcetype=zzz [search xxx | fields yy]

JohnMurphyAus
Path Finder

12 Years later, still the only solution I have managed to find!

Thank you 🙂

0 Karma

msallman
Explorer

Thanks. Piping through format in the subsearch works.

0 Karma

msallman
Explorer

Thanks for the info. I missed the description for format/maxresults when I was scanning through the limits.conf file.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...