Splunk Search

How to increase truncation limit to display all results in a chart?

Contributor

Hello Splunkers,

These results may be truncated. This visualization is configured to display a maximum of 1000 results per series, and that limit has been reached.

I am doing asset counts for the enterprise and am using charting to demonstrate them for high level reporting purposes. I see that my numbers appears to be coming out correctly within the Search "Events" tab details but trying to get visualization is difficult because I keep running into this limit. How do I increase it? I see some older references about XML or maybe a .conf file but nothing definite.

Any suggestions?

Thanks!

Tags (3)
1 Solution

Community Manager
Community Manager

Hi @lbogle

By default, chart results are truncated to 1000 as you've seen, but you can edit the limit by making a change to the charting.data.count value in simple XML. It's explained in the sub section of this documentation:
http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartDisplayissues#Search_result_truncation

You can change the value to whatever fits your needs, or you can set it to 0 to get all results as referenced here: http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartConfigurationReference#General_chart_prop...

Hope this solves your issue 🙂

Patrick

View solution in original post

Communicator

Have you opened a support case for this? We are trying to get Splunk to remove this limit and more customers behind this will help drive this.

Thanks,
Ken

0 Karma

Community Manager
Community Manager

Hi @lbogle

By default, chart results are truncated to 1000 as you've seen, but you can edit the limit by making a change to the charting.data.count value in simple XML. It's explained in the sub section of this documentation:
http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartDisplayissues#Search_result_truncation

You can change the value to whatever fits your needs, or you can set it to 0 to get all results as referenced here: http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartConfigurationReference#General_chart_prop...

Hope this solves your issue 🙂

Patrick

View solution in original post

Path Finder

charting.data.count worked for me and charting.chart.resultTruncationLimit did not work.

0 Karma

Path Finder

For me, it works with splunk 6.3.3 and does not work with 6.3.0.

0 Karma

Community Manager
Community Manager

Hi @lbogle

Hmm...did you try editing the XML for both the charting.chart.resultTruncationLimit property (http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/ChartDisplayissues#Configure_a_limit_on_a_per_... ) and charting.data.count property?

The only other helpful documentation I could find was this example:
http://docs.splunk.com/Documentation/Splunk/6.1.3/AdvancedDev/AdvChartingConfig-LayoutData#Data

0 Karma

Contributor

I tried the XML option but it didn't seem to work either. I also tried adjusting the limits.conf as suggested above. Restarted Splunk Web between modifications as well. Any other suggestions?

0 Karma

Contributor

Hi Patrick. Tried the web.conf fix but no go. Will try XML and get back to you.
Thanks

0 Karma

Path Finder

Hi,

I think you can change the setting in etc/system/default/limits.conf

If you look at this: http://docs.splunk.com/Documentation/Splunk/6.1.3/admin/Limitsconf it apears as though the setting you would want is "truncate_report".

Copy file to local, edit, and restart splunk.

Regards
Derek

0 Karma

Revered Legend

Communicator

Have you opened a case with Splunk for this? This is a hard limit which we have an enhancement request ticket open, more customers requesting this to be raised should push Splunk to fix this.

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!