Splunk Search

Likely Bug With Transaction MaxEvents

SplunkPersonal
Path Finder

Hello,

I'm using transaction to process events. Per the documentation (https://docs.splunk.com/Documentation/Splunk/7.2.0/SearchReference/Transaction), I set maxevents to a negative number so there is no limit. I only get 500 results however. But if I change maxevents to 5000 events, I get 2700 events with the exact same query.

Can you confirm this is not working as intended with a negative value for maxevents?

Thank you.

Tags (1)

simonzfor
Explorer

I have a similar issue where I have an expected of about 1500 events in a transaction. If I set maxevents to 1000, I get two different transactions. If I set maxevents to too big or disable it by using a negative value, they get excluded entirely from the end result. I find this behavior very strange.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...