Splunk Search

Saved Search only return 1000 rows

splunkgam
New Member

When a saved search sends an email with the results in a CSV file, the file never contains more than 1000 lines (plus the header line). How can I change this behavior to contain all the results found in the search, for instance 12000. When I run the same exact search manually in splunk, it returns 12000 rows, but the file will only contain 1000.

Tags (3)
0 Karma

Ayn
Legend

You should be able to modify the default limit of 1000 events by setting another value for maxresults in alert_actions.conf. See this question: http://splunk-base.splunk.com/answers/7544/splunk-alert-only-includes-first-1000-results-of-search-w...

splunkgam
New Member

Updating both default and local alert_actions.conf did not change the behavior. I did notice in the link you provided that one of the posters thought it might be because they were using 4.1.5 and that may have been part of the problem. We are using 4.1.4.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...

Supercharging Windows Security Detection Performance: Introducing Hybrid Field ...

Windows event logs—from Security auditing and Sysmon to PowerShell script blocks—form the operational backbone ...

Ditch the Manual Grind: Building AI Agents with Splunk

Ditch the Manual Grind: Building AI Agents with Splunk Let’s be real: your team’s time is being eaten alive. ...