Search limits

Prev Next

The following limits are imposed on Enterprise Searches to ensure that performance is not impacted and that the amount of data collected is useful.

  1. A maximum of 25 conditions can be used in a search. Error messages appear if you specify more than 25 conditions and the search will not run.

  2. A maximum of 15 searches can run concurrently, but this value is configurable. The default is set to five concurrent searches. If you attempt to run more concurrent searches than the configured maximum, error messages appear. For information on configuring this setting, see Limiting the number of concurrent searches .

  3. A maximum of 15 searches can be defined on the Enterprise Search page, but this value is configurable. The default is set to 10 searches. If you attempt to define more searches than the configured maximum, error messages appear. For information on configuring this setting, see Limiting the number of defined searches .

  4. A maximum of 1,000 rows can be returned in grid (Group By) mode and a maximum of 1,000 hosts matching the search criteria can be returned in host mode. Consider refining your search if the returned results exceed this limit.

    In grid (Group By) mode, any number of hosts can be processed, but no more than 1,000 unique grid rows display in the Web UI.

    When the data returned from an Enterprise Search includes multiple matches on nested items in the output, only the last match is listed on the Enterprise Search page. (ENDPT-3064)

    Note

    When the search results are downloaded to a CSV file, all of the data that is returned is included. The CSV file can contain more than 1,000 rows. See Reviewing search results .

  5. A maximum of 20 hits per host can be returned in host mode. If more than 20 hits are received, the extra hits for that host are ignored. Consider refining your search if the returned results exceed this limit.

  6. A maximum of 5 MB of data can be returned from a host endpoint. If the data returned by the EDRF Clientexceeds 5 MB, the agent truncates the payload. Consider refining your search if the returned results exceed this limit.