{"section":"known-issues","requestedLocale":"en","requestedSlug":"audit-csv-export-fails-for-large-result-sets-while-the-ui-reports-success","locale":"en","slug":"audit-csv-export-fails-for-large-result-sets-while-the-ui-reports-success","path":"docs/en/known-issues/VTEX Shield/audit-csv-export-fails-for-large-result-sets-while-the-ui-reports-success.md","branch":"main","content":"## Summary\n\nAudit CSV exports may fail for large result sets (long date ranges or many events), even though the search shows the results correctly in the UI. In some cases the UI shows a success message but the email never arrives; in others, it shows \"Export couldn't be completed. Try again.\" There is no fixed safe limit, because the failure depends on the total size of the events returned, not only on the number of events or days.\n\n## Simulation\n\n1. Go to **Admin > Account settings > Audit** (`/admin/audit`).\n2. Filter by an application with many events (for example, Site Editor, Promotions or Catalog) or by an action with many records (for example, `UserLogin`), with no other filters.\n3. Select a long date range (for example, 30 days or more) that returns thousands of events.\n4. Note that the results are shown correctly in the UI.\n5. Open the browser DevTools (`F12` or `Cmd+Option+I`), go to the **Network** tab and type `graphql` in the filter field.\n6. Click **Export to CSV**.\n7. Note what the UI shows: either the success message (but the email with the file never arrives, not even in spam) or the error \"Export couldn't be completed. Try again.\"\n\n**Checking the actual export status via Postman**\n\n1. In the **Network** tab, find the `POST` request to `https://{accountName}.myvtex.com/_v/private/graphql/v1?...` whose payload has the `exportLogStatus` query. To find it, click each `graphql` request and open the **Payload** tab, or type `exportLogStatus` in the Network search (`Cmd/Ctrl+F`).\n2. Right-click the request and choose **Copy > Copy as cURL (bash)**.\n3. In Postman, click **Import**, paste the cURL command as raw text and confirm. This creates a request with the URL, query params, headers (including the authentication cookie) and body already filled in.\n4. Click **Send** and check the response:\n\n\njson\n\n```\n{ \"data\": { \"exportLogStatus\": { \"status\": \"failed\", \"downloadUrls\": [], \"__typename\": \"ExportLogsStatus\" } }}\n```\n\n\n\nIf `status` is `failed` and `downloadUrls` is empty, the export job failed, even when the UI showed the success message. When an export succeeds, `downloadUrls` contains the link(s) to the generated file.\n\n> **Note:** the copied cURL has the user's session token (`VtexIdclientAutCookie`). Don't paste it in tickets, Slack or KI comments. If you share the request, remove the cookie first\n\n## Workaround\n\n- **Retry the export:** in some cases, retrying the same export after a few minutes works, because the data is partially cached after the first attempt. Wait for the previous attempt to finish (around 20 minutes) before trying again, since only one export per account is processed at a time.\n- **Split the export into smaller periods:** if retrying doesn't work, split the date range into smaller intervals (for example, weekly or daily instead of monthly) and export each one separately.\n- **Use more specific filters:** when possible, combine application and action filters to reduce the number of events per export."}