Splunk Search

Increasing rows returned from STAT \ CHART queries

apackard
Engager

When I run a CHART or STAT query, and the query returns more than 50 rows the output is truncated with the following:-

[and xx more values]

Is there anyway to increase the number of rows returned?

Tags (2)
0 Karma

sideview
SplunkTrust
SplunkTrust

This is a common mistake. You're running searches like

stats values(foo)

when you should be running

stats count by foo

instead. The former will return just one row, with "values(foo)" as a multivalue field. However it is designed for situations when there are only a few values, so it truncates at 50. The latter on the other hand will display any number of rows - hundreds, thousands, millions, and never truncate.

Similarly, if you find yourself doing stats values(foo) by bar, intending to get unique combinations of foo with bar, just do stats count by foo bar.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could also just do top 0 foo bar.

0 Karma
Get Updates on the Splunk Community!

Splunk APM & RUM | Upcoming Planned Maintenance

There will be planned maintenance of Splunk APM’s and Splunk RUM’s streaming infrastructure in the coming ...

Part 2: Diving Deeper With AIOps

Getting the Most Out of Event Correlation and Alert Storm Detection in Splunk IT Service Intelligence   Watch ...

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...