Splunk Search
Highlighted

How do I increase the limit on events returned when using cli search?

Path Finder

When running a splunk search from the cli, the maximum number of events returned is 100. How do I increase this limit?

Tags (3)
Highlighted

Re: How do I increase the limit on events returned when using cli search?

Communicator

-maxout 999 (or your preferred number)

View solution in original post

Highlighted

Re: How do I increase the limit on events returned when using cli search?

Explorer

I think what you are looking for is "-maxout NUM", which changes the limit of returned results from 100 to NUM.

View solution in original post

Highlighted

Re: How do I increase the limit on events returned when using cli search?

Motivator

New in 4.1, you can set -maxout 0, which means "unlimited." This is useful for streaming data to another processing system or to a file.

View solution in original post

Highlighted

Re: How do I increase the limit on events returned when using cli search?

Path Finder

As of 4.1.5 using -maxout 0 will yield unlimited results if your -ouput flag is set to 'raw' or 'rawdata', if it is set to 'csv' or 'table' it will be limited to 50k (plus one line for the header).

0 Karma
Highlighted

Re: How do I increase the limit on events returned when using cli search?

Motivator

csv is unlimited in 4.2. table remains limited.

0 Karma
Highlighted

Re: How do I increase the limit on events returned when using cli search?

Path Finder

Awesome!

:)

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.