<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Difference between the results from a visualizations and a regular search in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Difference-between-the-results-from-a-visualizations-and-a/m-p/406897#M4736</link>
    <description>&lt;P&gt;@cristiad by base search do you imply you are using Post-Processing? Is the final command in your base search a transforming command or streaming command? Will you be able to provide the query for existing dashboard?&lt;/P&gt;

&lt;P&gt;Make sure that you do not return all the fields using base search for post-processing and rather use transforming commands like stats. Refer to &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Viz/Savedsearches#Best_practices"&gt;Splunk Docs for Post-Processing Best Practices&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Aug 2018 09:43:31 GMT</pubDate>
    <dc:creator>niketn</dc:creator>
    <dc:date>2018-08-21T09:43:31Z</dc:date>
    <item>
      <title>Difference between the results from a visualizations and a regular search</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Difference-between-the-results-from-a-visualizations-and-a/m-p/406894#M4733</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;

&lt;P&gt;I have a strange situation. When I'm using a base search into a dashboard, I have displayed only 4 devices even if when I run the query as a regular search in search app I obtain a greater value.&lt;/P&gt;

&lt;P&gt;Any ideas?&lt;/P&gt;

&lt;P&gt;Thank you!&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5557i95D8E4FE5A02B413/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 11:17:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Difference-between-the-results-from-a-visualizations-and-a/m-p/406894#M4733</guid>
      <dc:creator>cristiad</dc:creator>
      <dc:date>2018-08-13T11:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between the results from a visualizations and a regular search</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Difference-between-the-results-from-a-visualizations-and-a/m-p/406895#M4734</link>
      <description>&lt;P&gt;Can you please elaborate on this?  Are you saying that you are using the same query and getting different results when you run it as adhoc regular search and when it is in a dashboard?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 22:49:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Difference-between-the-results-from-a-visualizations-and-a/m-p/406895#M4734</guid>
      <dc:creator>nadlurinadluri</dc:creator>
      <dc:date>2018-08-14T22:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between the results from a visualizations and a regular search</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Difference-between-the-results-from-a-visualizations-and-a/m-p/406896#M4735</link>
      <description>&lt;P&gt;Yes, the same search is used and I obtain different results.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 08:57:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Difference-between-the-results-from-a-visualizations-and-a/m-p/406896#M4735</guid>
      <dc:creator>cristiad</dc:creator>
      <dc:date>2018-08-21T08:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between the results from a visualizations and a regular search</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Difference-between-the-results-from-a-visualizations-and-a/m-p/406897#M4736</link>
      <description>&lt;P&gt;@cristiad by base search do you imply you are using Post-Processing? Is the final command in your base search a transforming command or streaming command? Will you be able to provide the query for existing dashboard?&lt;/P&gt;

&lt;P&gt;Make sure that you do not return all the fields using base search for post-processing and rather use transforming commands like stats. Refer to &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Viz/Savedsearches#Best_practices"&gt;Splunk Docs for Post-Processing Best Practices&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 09:43:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Difference-between-the-results-from-a-visualizations-and-a/m-p/406897#M4736</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-08-21T09:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between the results from a visualizations and a regular search</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Difference-between-the-results-from-a-visualizations-and-a/m-p/406898#M4737</link>
      <description>&lt;P&gt;This seems like you might have a knowledge object { field extraction or a lookup } that isnt set to export globally. &lt;/P&gt;

&lt;P&gt;Can you share your base search?&lt;/P&gt;

&lt;P&gt;,This sounds to me like you have some knowledge objects { lookup, field extraction } that dont have global permissions or is exported outside of an app context.. &lt;/P&gt;

&lt;P&gt;Can you share your base search? &lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 09:43:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Difference-between-the-results-from-a-visualizations-and-a/m-p/406898#M4737</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2018-08-21T09:43:53Z</dc:date>
    </item>
  </channel>
</rss>

