Thanks to a previous post you need to change two stanzas in the limits.conf.
[join] & [searchresults].
So for example I now have in $SPLUNK_HOME/etc/system/local/limits.conf:
[join]
subsearch_maxout = 500000
[searchresults]
maxresultrows = 500000
Note the above value is 500,000. I have added an extra 0 to the defaul
I believe this is because when you run the "join" in your query you are also using the "search" command so both parts are limiting you to the default of 50,000. i.e. joint FIELDNAME [search index=.....
... View more