Splunk Search

Impact of Increasing the limit of stats list() from 100 to say 1,00,000

ahmadshakir1952
Explorer

I am using stats list() for a use case. But the data I am dealing is lot more, than the limit that is set to =100 in limit.conf for stats list() function. I thought about using Stats Values(), but as it breaks the event order, I am stuck with stats list().

I am thinking of increasing the limit of stats list() from 100 to say 1,00,000 for example.

What I am concerned about is, will there be any performance issue if I increase the stats list() or will there be any problem if I increase it? Just to be on the safe side.

Any help would be appreciated.

0 Karma

to4kawa
Ultra Champion
| makeresults count=100000
| streamstats count
| stats list(count) as list_100000

Hi, @ahmadshakir1952
As I run this query, It is certainly omitted.

I don't know your query. What's your query?
There may be alternatives.

0 Karma

soumyasaha25
Contributor

On your question about the performance impact, you might end up running into OOM issues and your search performance might also get degraded, as suggested by @to4kawa there might be alternatives available, if you can post your query and some mockup data and the desired output we can try to help you out

0 Karma
Get Updates on the Splunk Community!

New Cloud Intrusion Detection System Add-on for Splunk

In July 2022 Splunk released the Cloud IDS add-on which expanded Splunk capabilities in security and data ...

Happy CX Day to our Community Superheroes!

Happy 10th Birthday CX Day!What is CX Day? It’s a global celebration recognizing innovation and success in the ...

Check out This Month’s Brand new Splunk Lantern Articles

Splunk Lantern is a customer success center providing advice from Splunk experts on valuable data insights, ...