<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk query not producing expected result in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-not-producing-expected-result/m-p/572252#M10451</link>
    <description>&lt;P&gt;Below query is producing expected result only sometime, but not working for similar data on some other random days.&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Query:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;index=my_summary source=app_response_status report=app_response_status ApiName=metadata&lt;BR /&gt;| timechart span=1d sum("200"), sum("404")&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Working Data:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;10/24/2021 00:00:00 +0000, search_name=app_response_status, search_now=1635123600.000, info_min_time=1635033600.000, info_max_time=1635120000.000, info_search_time=1635124485.280, 200=7552, 404=7582, ApiName=metadata, info_sid=scheduler__gmrm_VkEtdm1lLXJ0bXMtc2g__RMD50cd89fe00e4c64f8_at_1635123600_39072, RowTotals=15134, info_max_time="1635120000.000", info_min_time="1635033600.000", info_search_time="1635124485.280", report=app_response_status&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-10-25 at 5.18.46 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16569iC61714F7310C0AB5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-10-25 at 5.18.46 PM.png" alt="Screenshot 2021-10-25 at 5.18.46 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Not Working Data:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;09/03/2021 00:00:00 +0000, search_name=app_response_status, search_now=1630717200.000, info_min_time=1630627200.000, info_max_time=1630713600.000, info_search_time=1630717575.202, 200=9483, 404=5287, ApiName=metadata, info_sid=scheduler__gmrm_VkEtdm1lLXJ0bXMtc2g__RMD50cd89fe00e4c64f8_at_1630717200_72746, RowTotals=14770, info_max_time="1630713600.000", info_min_time="1630627200.000", info_search_time="1630717575.202", report=app_response_status&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-10-25 at 5.20.17 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16570i10562857B1231D1D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-10-25 at 5.20.17 PM.png" alt="Screenshot 2021-10-25 at 5.20.17 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I am not able to figure out the problem, both data looks same to me, but not sure why it is not working. pls help.&lt;/P&gt;</description>
    <pubDate>Mon, 25 Oct 2021 11:56:58 GMT</pubDate>
    <dc:creator>ravimishrabglr</dc:creator>
    <dc:date>2021-10-25T11:56:58Z</dc:date>
    <item>
      <title>Splunk query not producing expected result</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-not-producing-expected-result/m-p/572252#M10451</link>
      <description>&lt;P&gt;Below query is producing expected result only sometime, but not working for similar data on some other random days.&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Query:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;index=my_summary source=app_response_status report=app_response_status ApiName=metadata&lt;BR /&gt;| timechart span=1d sum("200"), sum("404")&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Working Data:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;10/24/2021 00:00:00 +0000, search_name=app_response_status, search_now=1635123600.000, info_min_time=1635033600.000, info_max_time=1635120000.000, info_search_time=1635124485.280, 200=7552, 404=7582, ApiName=metadata, info_sid=scheduler__gmrm_VkEtdm1lLXJ0bXMtc2g__RMD50cd89fe00e4c64f8_at_1635123600_39072, RowTotals=15134, info_max_time="1635120000.000", info_min_time="1635033600.000", info_search_time="1635124485.280", report=app_response_status&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-10-25 at 5.18.46 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16569iC61714F7310C0AB5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-10-25 at 5.18.46 PM.png" alt="Screenshot 2021-10-25 at 5.18.46 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Not Working Data:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;09/03/2021 00:00:00 +0000, search_name=app_response_status, search_now=1630717200.000, info_min_time=1630627200.000, info_max_time=1630713600.000, info_search_time=1630717575.202, 200=9483, 404=5287, ApiName=metadata, info_sid=scheduler__gmrm_VkEtdm1lLXJ0bXMtc2g__RMD50cd89fe00e4c64f8_at_1630717200_72746, RowTotals=14770, info_max_time="1630713600.000", info_min_time="1630627200.000", info_search_time="1630717575.202", report=app_response_status&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-10-25 at 5.20.17 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16570i10562857B1231D1D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-10-25 at 5.20.17 PM.png" alt="Screenshot 2021-10-25 at 5.20.17 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I am not able to figure out the problem, both data looks same to me, but not sure why it is not working. pls help.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 11:56:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-not-producing-expected-result/m-p/572252#M10451</guid>
      <dc:creator>ravimishrabglr</dc:creator>
      <dc:date>2021-10-25T11:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query not producing expected result</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-not-producing-expected-result/m-p/572265#M10452</link>
      <description>&lt;P&gt;Probably depends on what parsing rules you have for this sourcetype. Try to search for the first event and do&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| table *&lt;/LI-CODE&gt;&lt;P&gt;on it. Then do the same with the other one.&lt;/P&gt;&lt;P&gt;I'm not sure if you're not having some extra spaces before/after commas in one of the events but I can't tell if this breaks your parsing.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 13:04:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-query-not-producing-expected-result/m-p/572265#M10452</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-25T13:04:09Z</dc:date>
    </item>
  </channel>
</rss>

