Splunk Search

Top Limit 50000 results - Where to Change?

aferone
Builder

In my local limits.conf file, on my Search Head, I have the following:

[searchresults]

maxresultrows = 100000

[stats]

maxresultrows = 100000

However, I still get this error message:

"Error in 'top' command: The limit must be <= 50000."

Am I making the correct changes, and should they be on the Search Head or my Indexer?

Thanks!

Tags (3)
1 Solution

aferone
Builder

I added this to my limits.conf on the INDEXER, and it is now working.

[searchresults]

maxresultrows = 100000

[stats]

maxresultrows = 100000

[top]

maxresultrows = 100000

View solution in original post

aferone
Builder

Thank you!

0 Karma

somesoni2
Revered Legend

I see following text in the limits.conf documentation.
http://docs.splunk.com/Documentation/Splunk/6.1.1/admin/Limitsconf

*****limits.conf settings and DISTRIBUTED SEARCH
Unlike most settings which affect searches, limits.conf settings are not provided by the search head to be used by the search peers. This means that if you need to alter search-affecting limits in a distributed environment, typically you will need to modify these settings on the relevant peers and search head for consistent results.

aferone
Builder

I added this to my limits.conf on the INDEXER, and it is now working.

[searchresults]

maxresultrows = 100000

[stats]

maxresultrows = 100000

[top]

maxresultrows = 100000

aferone
Builder

Thank you, but there is no reference to whether this should be on the indexer or search head.

0 Karma

somesoni2
Revered Legend
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...