Splunk Search

Saved Search only return 1000 rows

New Member

When a saved search sends an email with the results in a CSV file, the file never contains more than 1000 lines (plus the header line). How can I change this behavior to contain all the results found in the search, for instance 12000. When I run the same exact search manually in splunk, it returns 12000 rows, but the file will only contain 1000.

Tags (3)
0 Karma


You should be able to modify the default limit of 1000 events by setting another value for maxresults in alert_actions.conf. See this question: http://splunk-base.splunk.com/answers/7544/splunk-alert-only-includes-first-1000-results-of-search-w...

New Member

Updating both default and local alert_actions.conf did not change the behavior. I did notice in the link you provided that one of the posters thought it might be because they were using 4.1.5 and that may have been part of the problem. We are using 4.1.4.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...