<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does anyone have an explanation for the differences in count with and without eval expression in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Does-anyone-have-an-explanation-for-the-differences-in-count/m-p/454673#M128644</link>
    <description>&lt;P&gt;hahah most welcome &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; &lt;/P&gt;</description>
    <pubDate>Tue, 14 May 2019 08:18:05 GMT</pubDate>
    <dc:creator>DavidHourani</dc:creator>
    <dc:date>2019-05-14T08:18:05Z</dc:date>
    <item>
      <title>Does anyone have an explanation for the differences in count with and without eval expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Does-anyone-have-an-explanation-for-the-differences-in-count/m-p/454670#M128641</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;on searching for discrepancies in my dashboard I was able to cut down the problem to the following to searches. Maybe there is an explanation for it. The difference is in the count of TLSv1.2.&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="search with eval"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7044iA3ADFFC14D9302C8/image-size/large?v=v2&amp;amp;px=999" role="button" title="search with eval" alt="search with eval" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="search without eval"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7045iF537729D5266A1C6/image-size/large?v=v2&amp;amp;px=999" role="button" title="search without eval" alt="search without eval" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 06:53:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Does-anyone-have-an-explanation-for-the-differences-in-count/m-p/454670#M128641</guid>
      <dc:creator>gesa_behrens</dc:creator>
      <dc:date>2019-05-14T06:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have an explanation for the differences in count with and without eval expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Does-anyone-have-an-explanation-for-the-differences-in-count/m-p/454671#M128642</link>
      <description>&lt;P&gt;Hi @gesa_behrens,&lt;/P&gt;

&lt;P&gt;This is happening because a single transaction contains sometimes more than one &lt;CODE&gt;ssl_protocol&lt;/CODE&gt; field values which means that if the condition matches on "-" everything gets replaced by the "HTTP" string. &lt;/P&gt;

&lt;P&gt;You might want to run your eval before building the transaction then you'll be good on the count.&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
David&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 07:08:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Does-anyone-have-an-explanation-for-the-differences-in-count/m-p/454671#M128642</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-14T07:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have an explanation for the differences in count with and without eval expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Does-anyone-have-an-explanation-for-the-differences-in-count/m-p/454672#M128643</link>
      <description>&lt;P&gt;wow, that was quick, and now that you mention it, this is absolutely clear to me, should have seen it my self.&lt;BR /&gt;
Thanks so much!&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 07:14:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Does-anyone-have-an-explanation-for-the-differences-in-count/m-p/454672#M128643</guid>
      <dc:creator>gesa_behrens</dc:creator>
      <dc:date>2019-05-14T07:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone have an explanation for the differences in count with and without eval expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Does-anyone-have-an-explanation-for-the-differences-in-count/m-p/454673#M128644</link>
      <description>&lt;P&gt;hahah most welcome &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 08:18:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Does-anyone-have-an-explanation-for-the-differences-in-count/m-p/454673#M128644</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-14T08:18:05Z</dc:date>
    </item>
  </channel>
</rss>

