<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: timechart count against si gives different max results for 2 intervals in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/timechart-count-against-si-gives-different-max-results-for-2/m-p/88978#M904</link>
    <description>&lt;P&gt;yeah that was the trick,,,,After the + hours the span=5 minutes is added, so thats why within the hour the results are 1/5 off ( just use 1 minute)&lt;/P&gt;</description>
    <pubDate>Mon, 10 Oct 2011 10:28:27 GMT</pubDate>
    <dc:creator>Starlette</dc:creator>
    <dc:date>2011-10-10T10:28:27Z</dc:date>
    <item>
      <title>timechart count against si gives different max results for 2 intervals</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/timechart-count-against-si-gives-different-max-results-for-2/m-p/88976#M902</link>
      <description>&lt;P&gt;I have si search "save" for every 5 mins as :&lt;/P&gt;

&lt;P&gt;search = sourcetype="cisco_firewall" | sitimechart count&lt;/P&gt;

&lt;P&gt;When running a report for last hour :&lt;BR /&gt;
search = index=summary marker=cisco_firewall_05 | timechart count&lt;/P&gt;

&lt;P&gt;I get line which is 200.000 events&lt;/P&gt;

&lt;P&gt;BUT when i ran a "last 4 hours", I get a line in the +1milion count.&lt;BR /&gt;
I doubt that i am using count over time wrong with si or is this unexpexted behaviour.&lt;/P&gt;

&lt;P&gt;if I take a look at a slice for 5 mins in e.g. last 30 mins i get &lt;/P&gt;

&lt;P&gt;10/10/11 11:30:00.000 AM 248483&lt;BR /&gt;
10/10/11 11:31:00.000 AM 252576&lt;BR /&gt;
10/10/11 11:32:00.000 AM 256538&lt;BR /&gt;
10/10/11 11:33:00.000 AM 249775&lt;BR /&gt;
10/10/11 11:34:00.000 AM 246672&lt;BR /&gt;
10/10/11 11:35:00.000 AM 245773&lt;/P&gt;

&lt;P&gt;And for last 4 hours i see 5 minutes bins wich are give the totals...&lt;/P&gt;

&lt;P&gt;10/10/11 9:45:00.000 AM  1166499&lt;BR /&gt;
10/10/11 9:50:00.000 AM  1201649&lt;BR /&gt;
10/10/11 9:55:00.000 AM  1170088&lt;BR /&gt;
10/10/11 10:00:00.000 AM 1186497&lt;BR /&gt;
10/10/11 10:05:00.000 AM 1189967&lt;/P&gt;

&lt;P&gt;So how to deal with this?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:58:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/timechart-count-against-si-gives-different-max-results-for-2/m-p/88976#M902</guid>
      <dc:creator>Starlette</dc:creator>
      <dc:date>2020-09-28T09:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: timechart count against si gives different max results for 2 intervals</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/timechart-count-against-si-gives-different-max-results-for-2/m-p/88977#M903</link>
      <description>&lt;P&gt;I would try setting the span on the timechart command as you may find it is trying to figure one out itself which is giving inconsistent results.&lt;BR /&gt;
Try span=5m to test &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2011 10:25:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/timechart-count-against-si-gives-different-max-results-for-2/m-p/88977#M903</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2011-10-10T10:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: timechart count against si gives different max results for 2 intervals</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/timechart-count-against-si-gives-different-max-results-for-2/m-p/88978#M904</link>
      <description>&lt;P&gt;yeah that was the trick,,,,After the + hours the span=5 minutes is added, so thats why within the hour the results are 1/5 off ( just use 1 minute)&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2011 10:28:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/timechart-count-against-si-gives-different-max-results-for-2/m-p/88978#M904</guid>
      <dc:creator>Starlette</dc:creator>
      <dc:date>2011-10-10T10:28:27Z</dc:date>
    </item>
  </channel>
</rss>

