Splunk Search

Hunk search only retrieves 1000 events. How to modify this limit?

benoitleroux
Explorer

Using Hunk, each search retrieves only 1000 results. Is this set in the etc/system/default/limits.conf? If so which key is it? I tried to modify some of them without success.

Tags (2)
1 Solution

rdagan_splunk
Splunk Employee
Splunk Employee

Try this: In limits.conf, change the following line. Default is 1000.
max_events_per_bucket = 1000

View solution in original post

benoitleroux
Explorer

Thanks it does affect it. max_events_per_bucket was not present in the fresh installed.

0 Karma

rdagan_splunk
Splunk Employee
Splunk Employee

Try this: In limits.conf, change the following line. Default is 1000.
max_events_per_bucket = 1000

benoitleroux
Explorer

Thanks it does affect it. max_events_per_bucket was not present etc/system/default/limits.conf in the fresh installed of last version.

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...