Splunk Search

Impact of Increasing the limit of stats list() from 100 to say 1,00,000

ahmadshakir1952
Explorer

I am using stats list() for a use case. But the data I am dealing is lot more, than the limit that is set to =100 in limit.conf for stats list() function. I thought about using Stats Values(), but as it breaks the event order, I am stuck with stats list().

I am thinking of increasing the limit of stats list() from 100 to say 1,00,000 for example.

What I am concerned about is, will there be any performance issue if I increase the stats list() or will there be any problem if I increase it? Just to be on the safe side.

Any help would be appreciated.

0 Karma

to4kawa
Ultra Champion
| makeresults count=100000
| streamstats count
| stats list(count) as list_100000

Hi, @ahmadshakir1952
As I run this query, It is certainly omitted.

I don't know your query. What's your query?
There may be alternatives.

0 Karma

soumyasaha25
Contributor

On your question about the performance impact, you might end up running into OOM issues and your search performance might also get degraded, as suggested by @to4kawa there might be alternatives available, if you can post your query and some mockup data and the desired output we can try to help you out

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...