When executing a query via the splunk SDK, apparently the results are clipped after 100 entries. How to get around this limit?
I tried:
>job = service.jobs.create(qstring,max_count=0, max_time=0, count=10000)
>while not job.is_ready():
time.sleep(1)
>out = list(results.ResultsReader(job.results()))
>print(len(out))
100
but the same query in the splunk web interface produces over 100 lines of results.
Try job.results(count=0) count=0 means no limit.
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With