Splunk Search

limited statistics results when running query via API

sushantnarula
Observer

Hi All,

I am running a query and getting limited results in Statistics field (10,000).
Earlier I was using the | sort command in the query, which was limiting the results to 10 K. but after removing it I am getting full results, and now when I am running the same query via API, I am still getting the limited 10 k results in statistics.

is this is a default configuration in splunk. Can I get full results running the query via API.

Thanks,
Sushant

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...