Splunk Search

Increasing rows returned from STAT \ CHART queries

apackard
Engager

When I run a CHART or STAT query, and the query returns more than 50 rows the output is truncated with the following:-

[and xx more values]

Is there anyway to increase the number of rows returned?

Tags (2)
0 Karma

sideview
SplunkTrust
SplunkTrust

This is a common mistake. You're running searches like

stats values(foo)

when you should be running

stats count by foo

instead. The former will return just one row, with "values(foo)" as a multivalue field. However it is designed for situations when there are only a few values, so it truncates at 50. The latter on the other hand will display any number of rows - hundreds, thousands, millions, and never truncate.

Similarly, if you find yourself doing stats values(foo) by bar, intending to get unique combinations of foo with bar, just do stats count by foo bar.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could also just do top 0 foo bar.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...