Splunk Search

How do I prevent my chart results from being truncated?

akazarov
Path Finder

Hello all,

I've seen a few similar discussions, but neither solution works for me - sorry for raising this again.

I have a search and a chart which produces big amount of results, and to plot it I use limiter
bins=2000 in my chart command. Yes, I want to display more then 1000 points on my UHD screen. But whatever chart options I use, it still complains with famous:

These results may be truncated. Your search generated too much data for the current visualization configuration.

and indeed the results are not complete. What I have in my chart XML code:

<option name="charting.data.count">3000</option>
<option name="charting.chart.resultTruncationLimit">3000</option>

Is there a working option? I could not find anything relevant in limits.conf. My splunk version is 6.3.0.

Thanks!

1 Solution

akazarov
Path Finder

I think this was resolved in the newer releases following 6.3.0.

View solution in original post

0 Karma

akazarov
Path Finder

I think this was resolved in the newer releases following 6.3.0.

0 Karma

kbecker
Communicator

Have you opened a support case for this? We are trying to get Splunk to remove this limit and more customers behind this will help drive this.

Thanks,
Ken

0 Karma

jplumsdaine22
Influencer

Have you seen: http://docs.splunk.com/Documentation/Splunk/6.3.0/Viz/ChartDisplayissues

Your code looks right, can you post the full XML? it may be that your tag is in the wrong spot. Also put your search string if possible

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...