On This Page

Home / Search/ Manage/ Usage Settings/Limits

Limits ​

Configure limits that apply to all searches performed in your Cribl Search instance.


You can configure limits that control search history and the granularity of search summaries displayed in the UI.

Limits listed in this section apply to all searches performed in your Cribl.Cloud Workspace. (You can define specific limits per user by configuring Usage Groups.)

Certain limits can be overridden by set statements in your queries.

When dynamic search concurrency is on, Cribl Search adjusts the maximum number of concurrent searches automatically based on current load.

List of Configurable System Limits ​

The following limits are available at Settings > Search > Limits:

  • Enable dynamic concurrency: When enabled, Cribl Search automatically adjusts the maximum number of concurrent searches based on CPU and memory pressure. This setting is on by default. For details, see Dynamic Search Concurrency.
  • Scheduled search jitter percent: Percentage of the scheduling interval to use as a random jitter window for scheduled searches. This spreads scheduled search execution times to reduce load spikes. You can override this limit for a specific scheduled search, using the Jitter percent setting.
    • Default is 20.
    • Minimum of 0, which disables jitter.
    • Maximum of 50.
  • Search history TTL: Amount of time to keep search artifacts around before removing them.
    • Default is 7d (7 days).
    • Minimum of 0, which instructs Cribl Search to not retain search artifacts at all.
    • You can override this limit for a specific scheduled search, using the Keep last executions setting.
    • Notebooks have a hard-coded 30-day retention period to facilitate extended investigations. Exceeding the Search history job limit will cause other jobs to be removed before Notebook jobs, to respect this extension.
  • Search history job limit: Maximum number of search jobs to retain before removing the oldest ones.
    • Default is 1000.
    • Minimum of 0.
    • You can override this limit for a specific scheduled search, using the Keep last executions setting.
  • Field summary nested depth limit: Maximum depth supported when building field summaries on nested object values. For example, x.y.z corresponds to the default depth of 3. Increase this default if you need to go deeper. For complex datasets with deeply nested structures, this limit prevents excessive resource consumption during field discovery.
    • Default is 3.
    • Minimum of 1.
  • Field summary breadth limit: Maximum number of distinct fields to include (before truncation) when generating field summaries on objects. Reduce this limit to improve performance with complex Datasets.
    • Default is 200.
    • Minimum of 0.
  • Prevent revealing Dataset Provider secrets (Admin only): When enabled, credentials used for configuring Dataset Providers (such as secret keys) are obfuscated.
    • Default is Yes.

List of Fixed System Limits ​

The following limits are not configurable:

  • Field size limit: Maximum per-field payload size enforced on fields (like _raw). When results are rendered, Cribl Search will truncate or omit oversized payloads to maintain responsiveness. This limit applies to all searches.
    • Set to 2 MB per field, and not configurable.
  • Numeric precision limit (Lakehouse only): Integer literals in queries are limited to the IEEE 754 safe integer range (±(2^53 - 1), or ±9,007,199,254,740,991). Integers outside this range, and values that overflow Float64 to infinity (such as 1e309), are automatically treated as strings in Lakehouse searches. To search on a large numeric value as a string, enclose it in quotes. For details and examples, see Numeric Precision Limits for Large Integers.