Splunk Search

Is there a limit on the search terms or the number of AND/OR conditions?

nareerat_pr
Explorer

I create a search query as follows:

sourcetype="websense:proxy"

| table src_host policy

| dedup src_host policy

| search NOT [inputlookup ip_white_list.csv]

The ip_white_list.csv file contains 2 columns  (policy,src_host) and 21,435 rows.

I found some src_host are not filtered out from the search result

so I want to know Is there a limit on the search terms or the number of AND/OR conditions?

Labels (1)
0 Karma

to4kawa
Ultra Champion

https://docs.splunk.com/Documentation/Splunk/latest/Search/Aboutsubsearches

your csv has much rows.

please modify limits.conf

0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...