<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Stats count discrepancy in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413410#M50482</link>
    <description>&lt;P&gt;Version is 7.0.4. The problematic sources are from Splunk App DBConnect version 3.1.3&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jun 2018 07:31:38 GMT</pubDate>
    <dc:creator>tiagofbmm</dc:creator>
    <dc:date>2018-06-29T07:31:38Z</dc:date>
    <item>
      <title>Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413385#M50457</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;How would searching in VERBOSE mode and a strict timerange for &lt;CODE&gt;index=foo host=bar | stats count&lt;/CODE&gt; return a much larger value than the number of events I see &lt;/P&gt;

&lt;P&gt;Even if I search for &lt;CODE&gt;index=foo host=bar&lt;/CODE&gt; in the same time frame I have much less events than what the count reports. What is wrong? How can Splunk count the events with a specific host but then not returning them?&lt;/P&gt;

&lt;P&gt;Any ideas?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;P.S.:please note the attachments evidence&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 16:15:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413385#M50457</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2018-06-28T16:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413386#M50458</link>
      <description>&lt;P&gt;@tiagofbmm, Wow strange. Can you post a snapshot if possible and Splunk version please?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Sandeep&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 17:27:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413386#M50458</guid>
      <dc:creator>sandeeprachuri</dc:creator>
      <dc:date>2018-06-28T17:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413387#M50459</link>
      <description>&lt;P&gt;By strict timerange, are you referring to non-relative time? &lt;/P&gt;

&lt;P&gt;So when you run stats, its returning a value of 1 and when you strip off stats its returning zero events? &lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 17:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413387#M50459</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-06-28T17:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413388#M50460</link>
      <description>&lt;P&gt;I can't put screenshots but the version is 7.0. The searches I've done are exactly as I told you though&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 17:38:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413388#M50460</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2018-06-28T17:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413389#M50461</link>
      <description>&lt;P&gt;Yes, not a relative time. Stats count is returning a count of for instance 290, but no events at all show up&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 17:39:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413389#M50461</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2018-06-28T17:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413390#M50462</link>
      <description>&lt;P&gt;Yes it is just like that. Stats shows there are events in that index from that host but stripping the stats off, I see no events. Weirdest thing &lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 19:19:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413390#M50462</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2018-06-28T19:19:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413391#M50463</link>
      <description>&lt;P&gt;Does this happens for this one sourcetype only? How big are your raw data for this sourcetype?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 19:41:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413391#M50463</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-06-28T19:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413392#M50464</link>
      <description>&lt;P&gt;It's happening to dbinput sources from dbconnect. Raw data is not very big, these are audit logs. Size is not uncommon&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 19:45:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413392#M50464</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2018-06-28T19:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413393#M50465</link>
      <description>&lt;P&gt;Does it do this even if you choose All Time?  What time frame are you choosing?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 19:52:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413393#M50465</guid>
      <dc:creator>scannon4</dc:creator>
      <dc:date>2018-06-28T19:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413394#M50466</link>
      <description>&lt;P&gt;Strange Indeed. Do you get results in statistics tab with something like this?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=foo host=bar | table _time _raw
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Also, did  you try running it in different browser?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 19:53:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413394#M50466</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-06-28T19:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413395#M50467</link>
      <description>&lt;P&gt;It happens for non relative time windows, such as yesterday, or a specific hour for the day. &lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 19:54:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413395#M50467</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2018-06-28T19:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413396#M50468</link>
      <description>&lt;P&gt;I didn't try to run it in a different browser. Currently running on Chrome. About tabling the raw and time fields, as it does not show anything at all by the search itself and it returns raw as default, I didn't try it. Will come back here when I have the result of that&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 19:59:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413396#M50468</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2018-06-28T19:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413397#M50469</link>
      <description>&lt;P&gt;Very interesting.  I use dbconnect so I decided to try it too.  I see events.  Wish I could see what you are seeing.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 20:03:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413397#M50469</guid>
      <dc:creator>scannon4</dc:creator>
      <dc:date>2018-06-28T20:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413398#M50470</link>
      <description>&lt;P&gt;If you do index=foo without the host, do you see events from other hosts?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 20:03:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413398#M50470</guid>
      <dc:creator>scannon4</dc:creator>
      <dc:date>2018-06-28T20:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413399#M50471</link>
      <description>&lt;P&gt;Will try to show exactly what I am seing now. It's mostly incredible I must say&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 20:07:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413399#M50471</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2018-06-28T20:07:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413400#M50472</link>
      <description>&lt;P&gt;The issue is not really about not seing any event. It's about seing a really small fraction of the events comparing to what the count shows. &lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 20:08:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413400#M50472</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2018-06-28T20:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413401#M50473</link>
      <description>&lt;P&gt;Then why does your question say:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;I don't see any events in the events tab&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Which is it? Do you see no events, or not enough events? And if the latter, how many are you seeing and what is the count from the &lt;CODE&gt;stats&lt;/CODE&gt; command?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 20:26:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413401#M50473</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2018-06-28T20:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413402#M50474</link>
      <description>&lt;P&gt;I would use Job Inspector as well to look at every step the search took to make sure nothing weird is going on with an indexer or something.  Just a thought.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 21:02:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413402#M50474</guid>
      <dc:creator>scannon4</dc:creator>
      <dc:date>2018-06-28T21:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413403#M50475</link>
      <description>&lt;P&gt;It is a discrepancy between the count and the events I see by searching them. If I narrow it enough it will get to the point where I see no events and the count to be a positive  number. But wider ranges, I see much less events than the one the count shows&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 21:21:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413403#M50475</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2018-06-28T21:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stats count discrepancy</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413404#M50476</link>
      <description>&lt;P&gt;Have you filed a support case with Splunk?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 21:39:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stats-count-discrepancy/m-p/413404#M50476</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2018-06-28T21:39:37Z</dc:date>
    </item>
  </channel>
</rss>

