<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: In Splunk Free Version, why is the same search query returning different results? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/In-Splunk-Free-Version-why-is-the-same-search-query-returning/m-p/456311#M129000</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I think I found why: afterrunning the search, when I click on "job", it displays:&lt;BR /&gt;
"Search auto-finalized after disk usage limit (0MB) reached "&lt;/P&gt;

&lt;P&gt;I read through documentation, and found this can be  controlled with setting the value for "srchDiskQuota"  in&lt;BR /&gt;
"authentication.conf", which I did:&lt;/P&gt;

&lt;P&gt;[role_admin]&lt;BR /&gt;
srchDiskQuota   = 500&lt;/P&gt;

&lt;P&gt;Then restarting Spluk.&lt;BR /&gt;
I am afraid: This did not help, still same behaviour.&lt;BR /&gt;
I guess: Since there are no "real" roles in Splunk free, it is not possible to set this parameter manually by changing "authentication.conf" .&lt;/P&gt;

&lt;P&gt;My theory is: I guess for Splunk Free, this value is set to "0" to "encourage" people to get a real license, bc. bigger searches  will have the auto-finalized status?&lt;BR /&gt;
Can you please confirm if this is the case? If yes, I suggest to to also update "Splunk Free vs. Splunk Enterprise" documentation, so people know about this limitation.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;

&lt;P&gt;Best Regards&lt;BR /&gt;
Florian&lt;/P&gt;</description>
    <pubDate>Fri, 14 Sep 2018 08:27:58 GMT</pubDate>
    <dc:creator>flopit</dc:creator>
    <dc:date>2018-09-14T08:27:58Z</dc:date>
    <item>
      <title>In Splunk Free Version, why is the same search query returning different results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/In-Splunk-Free-Version-why-is-the-same-search-query-returning/m-p/456310#M128999</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have Splunk Free (I am afraid this is not present in the "choose product" list, switched from "Enterprise Trial"...).&lt;/P&gt;

&lt;P&gt;I am using the same user (there is only admin user in Splunk Free), and I have tried to run a very simple query several times,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host="abc-def.csv"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The time picker = "All time". &lt;/P&gt;

&lt;P&gt;Moreover, the index records do not change during the searches (one time load CSV). &lt;/P&gt;

&lt;P&gt;Also, settings for event sampling are "No event sampling".&lt;/P&gt;

&lt;P&gt;Now, strangely, I always get a different amount of events returned (e.g. ranging from 132k to 169k events...).&lt;/P&gt;

&lt;P&gt;Why is this so? Is there kind of timeout and how can I increase it?&lt;/P&gt;

&lt;P&gt;There are several similar posts, but all are n.a. - e.g. I use a single user and the index does not change, ...&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;

&lt;P&gt;Best Regards&lt;BR /&gt;
Florian&lt;/P&gt;</description>
      <pubDate>Wed, 12 Sep 2018 08:37:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/In-Splunk-Free-Version-why-is-the-same-search-query-returning/m-p/456310#M128999</guid>
      <dc:creator>flopit</dc:creator>
      <dc:date>2018-09-12T08:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk Free Version, why is the same search query returning different results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/In-Splunk-Free-Version-why-is-the-same-search-query-returning/m-p/456311#M129000</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I think I found why: afterrunning the search, when I click on "job", it displays:&lt;BR /&gt;
"Search auto-finalized after disk usage limit (0MB) reached "&lt;/P&gt;

&lt;P&gt;I read through documentation, and found this can be  controlled with setting the value for "srchDiskQuota"  in&lt;BR /&gt;
"authentication.conf", which I did:&lt;/P&gt;

&lt;P&gt;[role_admin]&lt;BR /&gt;
srchDiskQuota   = 500&lt;/P&gt;

&lt;P&gt;Then restarting Spluk.&lt;BR /&gt;
I am afraid: This did not help, still same behaviour.&lt;BR /&gt;
I guess: Since there are no "real" roles in Splunk free, it is not possible to set this parameter manually by changing "authentication.conf" .&lt;/P&gt;

&lt;P&gt;My theory is: I guess for Splunk Free, this value is set to "0" to "encourage" people to get a real license, bc. bigger searches  will have the auto-finalized status?&lt;BR /&gt;
Can you please confirm if this is the case? If yes, I suggest to to also update "Splunk Free vs. Splunk Enterprise" documentation, so people know about this limitation.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;

&lt;P&gt;Best Regards&lt;BR /&gt;
Florian&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 08:27:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/In-Splunk-Free-Version-why-is-the-same-search-query-returning/m-p/456311#M129000</guid>
      <dc:creator>flopit</dc:creator>
      <dc:date>2018-09-14T08:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk Free Version, why is the same search query returning different results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/In-Splunk-Free-Version-why-is-the-same-search-query-returning/m-p/456312#M129001</link>
      <description>&lt;P&gt;What is the release number of your Splunk installation? 7.1.1 maybe?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 13:56:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/In-Splunk-Free-Version-why-is-the-same-search-query-returning/m-p/456312#M129001</guid>
      <dc:creator>janispelss</dc:creator>
      <dc:date>2018-09-14T13:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk Free Version, why is the same search query returning different results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/In-Splunk-Free-Version-why-is-the-same-search-query-returning/m-p/456313#M129002</link>
      <description>&lt;P&gt;I had the same idea, downloaded and upgraded to 7.1.3, now all is good again!&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 14:05:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/In-Splunk-Free-Version-why-is-the-same-search-query-returning/m-p/456313#M129002</guid>
      <dc:creator>flopit</dc:creator>
      <dc:date>2018-09-14T14:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: In Splunk Free Version, why is the same search query returning different results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/In-Splunk-Free-Version-why-is-the-same-search-query-returning/m-p/456314#M129003</link>
      <description>&lt;P&gt;Upgrade to 7.1.3. helped! Now all looks good, no more "Search auto-finalized after disk usage limit (0MB) reached ".&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 14:06:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/In-Splunk-Free-Version-why-is-the-same-search-query-returning/m-p/456314#M129003</guid>
      <dc:creator>flopit</dc:creator>
      <dc:date>2018-09-14T14:06:32Z</dc:date>
    </item>
  </channel>
</rss>

