Splunk Search

How to increase limit of "The pipeline size limit"?

ktc78
Explorer

Hi all,

I just upgraded splunk enterprise from 8.1.2 to 8.2.6.1
And I found some of big searches return below message when I run them

 

"Error in 'SearchPipeline': The pipeline size for this search exceeds a search command limit : 340"

 

I've never seen this message on 8.1.2 before

Could you please guide me 'which conf file stanza should be modified to increase pipeline limit?'

0 Karma

cklunck
Path Finder

It appears the limit of 340 commands in a search pipeline is a hard-coded value and cannot be increased.

I was able to find this previous Community post which applies to your situation:

Executed search contains more than 340 commands 

0 Karma

ktc78
Explorer

Thanks you cklunck for your kind reply!

I'm sure that's why I can't find any conf files nor articles about that...

Anyway I'm afraid I haven't read that restrictions in splunk release notes at all 😞

Tags (1)
0 Karma

ktc78
Explorer

Below is official answer I got from splunk support team

--- Message ---

The limit is a hidden setting.

We don't recommend our customers to modify it, as searches with hundreds of search commands can cause crashes. 

 To prevent crashes, in 8.2.3 we changed the limit to 340.

 In 9.0.0, we made some more fundamental changes to address the root cause of the crashing, so the limit is set to 1000.

 We would recommend upgrading your Splunk Enterprise instances to 9.0.0 or later.

 [Ref] https://docs.splunk.com/Documentation/Splunk/9.0.0/ReleaseNotes/Fixedissues#:~:text=Searches%20with%...

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...