<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are we receiving inconsistent data? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-receiving-inconsistent-data/m-p/303426#M11481</link>
    <description>&lt;P&gt;Yes these are search heads apart of the cluster.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Feb 2017 18:07:27 GMT</pubDate>
    <dc:creator>vxl65703</dc:creator>
    <dc:date>2017-02-14T18:07:27Z</dc:date>
    <item>
      <title>Why are we receiving inconsistent data?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-receiving-inconsistent-data/m-p/303422#M11477</link>
      <description>&lt;P&gt;I am a first time, I have a user who says his search heads are kicking different results on two different search heads.&lt;/P&gt;

&lt;P&gt;We are using Splunk 6.3&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 15:00:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-receiving-inconsistent-data/m-p/303422#M11477</guid>
      <dc:creator>vxl65703</dc:creator>
      <dc:date>2017-02-14T15:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we receiving inconsistent data?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-receiving-inconsistent-data/m-p/303423#M11478</link>
      <description>&lt;P&gt;Are the search heads in cluster? or independent? You might want to verify the search peers for both of these search heads. You will have to ask more details to your user like what is the search? time range selected? Is he using any lookups that are available on one SH and not other? Are the results always consistently different ? Did he take a look at the job inspector to see if there were any errors from a search peer that had trouble sending data back ?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 16:18:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-receiving-inconsistent-data/m-p/303423#M11478</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2017-02-14T16:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we receiving inconsistent data?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-receiving-inconsistent-data/m-p/303424#M11479</link>
      <description>&lt;P&gt;the search heads are in a cluster, one instance pulls up data the other instance only pulls up a part of the data, would.&lt;/P&gt;

&lt;P&gt;Would need to look at the indexers or forwarders to see if either is corrupt ?&lt;/P&gt;

&lt;P&gt;Would I need to SSH into the servers to review the indexers/forwarders ?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 16:45:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-receiving-inconsistent-data/m-p/303424#M11479</guid>
      <dc:creator>vxl65703</dc:creator>
      <dc:date>2017-02-14T16:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we receiving inconsistent data?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-receiving-inconsistent-data/m-p/303425#M11480</link>
      <description>&lt;P&gt;To be sure, these search heads are part of a SEARCH HEAD CLUSTER?  Yes/no?&lt;/P&gt;

&lt;P&gt;Noting SEARCH HEAD CLUSTER is not the same as a SPLUNK CLUSTER (which is the general term used for a cluster of indexers, a cluster master, license master, and search head(s))&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 17:19:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-receiving-inconsistent-data/m-p/303425#M11480</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-02-14T17:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we receiving inconsistent data?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-receiving-inconsistent-data/m-p/303426#M11481</link>
      <description>&lt;P&gt;Yes these are search heads apart of the cluster.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 18:07:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-receiving-inconsistent-data/m-p/303426#M11481</guid>
      <dc:creator>vxl65703</dc:creator>
      <dc:date>2017-02-14T18:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we receiving inconsistent data?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-receiving-inconsistent-data/m-p/303427#M11482</link>
      <description>&lt;P&gt;-hangs head-&lt;/P&gt;

&lt;P&gt;Are they part of a search head cluster?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 18:17:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-receiving-inconsistent-data/m-p/303427#M11482</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-02-14T18:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we receiving inconsistent data?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-receiving-inconsistent-data/m-p/303428#M11483</link>
      <description>&lt;P&gt;Yes they are a part of a search head cluster&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 19:52:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-receiving-inconsistent-data/m-p/303428#M11483</guid>
      <dc:creator>vxl65703</dc:creator>
      <dc:date>2017-02-14T19:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we receiving inconsistent data?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-receiving-inconsistent-data/m-p/303429#M11484</link>
      <description>&lt;P&gt;Have them give you the exact search they are running, and the results. &lt;/P&gt;

&lt;P&gt;First, make sure that the search they are kicking off is a consistent search.  Make sure it has a fixed earliest and latest value, and so on.   If they are kicking off "last 30 minutes" on one head then later on another had, then of course the answer will be different.  &lt;/P&gt;

&lt;P&gt;Second, run that query yourself on each head.  See if your results are the same or different from his.  Ideally, limit the search to as small a time range and amount of detail as possible, as long as he gets a different result on each head.&lt;/P&gt;

&lt;P&gt;If there are lookups in the search, or joins, then run those subsearches independently and check whether they are consistent on the two heads.  Perhaps a lookup isn't propagating fully, or whatever.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 22:34:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-receiving-inconsistent-data/m-p/303429#M11484</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-02-14T22:34:13Z</dc:date>
    </item>
  </channel>
</rss>

