Splunk Search

Splunk Search results limit 4999

kc_prane
Communicator

Hello, 

Currently, I am using the append command to combine two queries and tabulate the results, but I see only 4999 transactions. Is there any way I can get full results?  Thanks in advance!

Labels (1)
Tags (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

append and subsearches have limitations and limits defined in limits.conf, so you cannot override these, but that number seems an odd number. 

What is your search - there are often alternatives to append and a subsearch.

Can you share your search

0 Karma

kc_prane
Communicator

Hi @bowesman Thanks for the reply Please find the below snap shots for the query. I had masked my base search.. fyi  my base search is same for the subsearch as well.

kc_prane_0-1699495212563.png

 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

OK, so a lot going on here...

You have two searches that look similar - not sure if they are searching the same data set, but in order to diagnose this you should do a number of things. You are also using the transaction command that also has limitations and can cause data not to appear if you hit those limitations - and you will not know about it.

I suggest you validate first search 1 and see how many results you expect and then run search 2 (the appended data) and determine how many you see then.

If you do not see 1 + 2 in the combined search, you are hitting some memory issue.

I suspect, but cannot say exactly, that you could remove both the append and the use of transaction and just use stats. 

Are the two masked search data sets the same or different?

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @kc_prane ,

using a screenshot and masking your search we cannot help you!

@bowesmana was saying that probably you don't need to use append and you can put both the searches in the main search, in this way you don't have any limit.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...