Splunk Search

Hunk search only retrieves 1000 events. How to modify this limit?

benoitleroux
Explorer

Using Hunk, each search retrieves only 1000 results. Is this set in the etc/system/default/limits.conf? If so which key is it? I tried to modify some of them without success.

Tags (2)
1 Solution

rdagan_splunk
Splunk Employee
Splunk Employee

Try this: In limits.conf, change the following line. Default is 1000.
max_events_per_bucket = 1000

View solution in original post

benoitleroux
Explorer

Thanks it does affect it. max_events_per_bucket was not present in the fresh installed.

0 Karma

rdagan_splunk
Splunk Employee
Splunk Employee

Try this: In limits.conf, change the following line. Default is 1000.
max_events_per_bucket = 1000

benoitleroux
Explorer

Thanks it does affect it. max_events_per_bucket was not present etc/system/default/limits.conf in the fresh installed of last version.

0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...