Changes made in limits.conf:
Path of the file: /data/third_party/splunk/etc/system/local
Under [searchresults], maxresultsrow
changes the value from 50000 to 500000.
But still see, only 50000 results for any Query to Splunk, though there are 5600000 Events existing in the database.
For the information:
vm30esa0072:rtestuser 116] /data/third_party/splunk/bin/splunk dispatch "* starttime=04/11/2017:00:00:00 endtime=04/12/2017:23:59:00 | stats count" -auth admin:changeme
count
1686815
==> Totally there are 16 Lakhs around Events/Results in the Splunk DB. But get only 50K Results...!!
limits.conf file snippet:
[searchresults]
maxresultrows = 5000000
tocsv_maxretry = 5
tocsv_retryperiod_ms = 500