Splunk Search

How do I prevent my chart results from being truncated?

akazarov
Path Finder

Hello all,

I've seen a few similar discussions, but neither solution works for me - sorry for raising this again.

I have a search and a chart which produces big amount of results, and to plot it I use limiter
bins=2000 in my chart command. Yes, I want to display more then 1000 points on my UHD screen. But whatever chart options I use, it still complains with famous:

These results may be truncated. Your search generated too much data for the current visualization configuration.

and indeed the results are not complete. What I have in my chart XML code:

<option name="charting.data.count">3000</option>
<option name="charting.chart.resultTruncationLimit">3000</option>

Is there a working option? I could not find anything relevant in limits.conf. My splunk version is 6.3.0.

Thanks!

1 Solution

akazarov
Path Finder

I think this was resolved in the newer releases following 6.3.0.

View solution in original post

0 Karma

akazarov
Path Finder

I think this was resolved in the newer releases following 6.3.0.

0 Karma

kbecker
Communicator

Have you opened a support case for this? We are trying to get Splunk to remove this limit and more customers behind this will help drive this.

Thanks,
Ken

0 Karma

jplumsdaine22
Influencer

Have you seen: http://docs.splunk.com/Documentation/Splunk/6.3.0/Viz/ChartDisplayissues

Your code looks right, can you post the full XML? it may be that your tag is in the wrong spot. Also put your search string if possible

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...