<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Number of events found not matching number of events displayed in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Number-of-events-found-not-matching-number-of-events-displayed/m-p/296178#M165626</link>
    <description>&lt;P&gt;Sorry for my ignorance, but when I run that command, I am not sure where in the output I am seeing IOPS. I did some research and saw advise for getting IOPS measurements from the linux command iostat. Because my $SPLUNKHOME is on device dm-6, I ran:&lt;BR /&gt;
    iostat -d dm-6 5&lt;BR /&gt;
Scrolling output looks like this:&lt;BR /&gt;
    Device:            tps    kB_read/s    kB_wrtn/s    kB_read    kB_wrtn&lt;BR /&gt;
    dm-6            240.80         0.00     12054.10          0      60270&lt;BR /&gt;
tps is ranging between very low (&amp;lt;1) and ~400.&lt;/P&gt;

&lt;P&gt;There are some errors in splunkd.log, but they are unrelated. Most have to do with an incorrect parsing of our ingested /var/log/messages (a separate issue I am working with our ops team to resolve).&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 16:10:21 GMT</pubDate>
    <dc:creator>elliotproebstel</dc:creator>
    <dc:date>2020-09-29T16:10:21Z</dc:date>
    <item>
      <title>Number of events found not matching number of events displayed</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Number-of-events-found-not-matching-number-of-events-displayed/m-p/296174#M165622</link>
      <description>&lt;P&gt;Our Splunk Enterprise deployment has started returning inconsistent results, and I've been unable to track the source of the issue. In one example, Splunk reports that it found 34 results matching the search query, but the event viewer tab below only displays 9 of the results. I ran this same query &amp;gt;10 times (without any changes in search terms or time window) on our search head and received this inconsistent answer about 50% of the time. Here is a screenshot:&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3623i61C8F5D128D5FF87/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Additionally, some queries are returning with very large numbers of reported results but displaying no results at all in the event viewer. The large number of results is expected; the query is somewhat complex and broad. But this query structure has worked consistently for us for over a year, and suddenly it is producing these inexplicable results:&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3624iAFC1BCA4DC70CB65/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;It is probably relevant to mention that we used to be using two independent search heads connected to a pool of ~10 indexers. We have recently moved to a new set of two search heads connected to a new pool of ~10 indexers - all of which is mirrored at another site, where the original equipment is being used as a replicated backup. &lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 19:46:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Number-of-events-found-not-matching-number-of-events-displayed/m-p/296174#M165622</guid>
      <dc:creator>elliotproebstel</dc:creator>
      <dc:date>2017-10-12T19:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: Number of events found not matching number of events displayed</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Number-of-events-found-not-matching-number-of-events-displayed/m-p/296175#M165623</link>
      <description>&lt;P&gt;Interesting.. What's the message in the &lt;CODE&gt;Job&lt;/CODE&gt; dropdown menu say?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 19:56:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Number-of-events-found-not-matching-number-of-events-displayed/m-p/296175#M165623</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-10-12T19:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: Number of events found not matching number of events displayed</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Number-of-events-found-not-matching-number-of-events-displayed/m-p/296176#M165624</link>
      <description>&lt;P&gt;It says:&lt;BR /&gt;
&lt;EM&gt;[myhost] Dispatch Runner: Configuration initialization for /opt/splunk/var/run/searchpeers/myhost-1507751096 took longer than expected (1960ms) when dispatching a search (search ID: remote_myhost_1507751400.34954); this typically reflects underlying storage performance issues&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;We have also been seeing this error a lot lately, but our Splunk admin/architect team (who have now left the organization) indicated that this was related to the migration we were undergoing and that it would resolve after the migration was completed. I believe the migration is now complete, and this error continues to appear more frequently than not.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:09:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Number-of-events-found-not-matching-number-of-events-displayed/m-p/296176#M165624</guid>
      <dc:creator>elliotproebstel</dc:creator>
      <dc:date>2020-09-29T16:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: Number of events found not matching number of events displayed</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Number-of-events-found-not-matching-number-of-events-displayed/m-p/296177#M165625</link>
      <description>&lt;P&gt;Let's take a look at your IOPS.. Run this command &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;| rest /services/server/info&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Any errors in &lt;CODE&gt;splunkd.log&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 21:03:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Number-of-events-found-not-matching-number-of-events-displayed/m-p/296177#M165625</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-10-12T21:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: Number of events found not matching number of events displayed</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Number-of-events-found-not-matching-number-of-events-displayed/m-p/296178#M165626</link>
      <description>&lt;P&gt;Sorry for my ignorance, but when I run that command, I am not sure where in the output I am seeing IOPS. I did some research and saw advise for getting IOPS measurements from the linux command iostat. Because my $SPLUNKHOME is on device dm-6, I ran:&lt;BR /&gt;
    iostat -d dm-6 5&lt;BR /&gt;
Scrolling output looks like this:&lt;BR /&gt;
    Device:            tps    kB_read/s    kB_wrtn/s    kB_read    kB_wrtn&lt;BR /&gt;
    dm-6            240.80         0.00     12054.10          0      60270&lt;BR /&gt;
tps is ranging between very low (&amp;lt;1) and ~400.&lt;/P&gt;

&lt;P&gt;There are some errors in splunkd.log, but they are unrelated. Most have to do with an incorrect parsing of our ingested /var/log/messages (a separate issue I am working with our ops team to resolve).&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:10:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Number-of-events-found-not-matching-number-of-events-displayed/m-p/296178#M165626</guid>
      <dc:creator>elliotproebstel</dc:creator>
      <dc:date>2020-09-29T16:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: Number of events found not matching number of events displayed</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Number-of-events-found-not-matching-number-of-events-displayed/m-p/296179#M165627</link>
      <description>&lt;P&gt;I believe this is related to SPL-142964, with the workaround referenced &lt;A href="https://answers.splunk.com/answers/567121/number-of-returned-events-doesnt-equal-number-of-e.html"&gt;here&lt;/A&gt;.  It should be fixed in 6.6.4.&lt;/P&gt;

&lt;P&gt;I doubt this late answer solves anything, but wanted to put the response here so the question could be marked as answered.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 19:40:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Number-of-events-found-not-matching-number-of-events-displayed/m-p/296179#M165627</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2017-12-28T19:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: Number of events found not matching number of events displayed</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Number-of-events-found-not-matching-number-of-events-displayed/m-p/296180#M165628</link>
      <description>&lt;P&gt;We implemented the workaround and did not find that it solved the issue for us. We are working on getting authorization to roll out 6.6.4, and I'll try to remember to update this post when we are able to do so.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 18:50:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Number-of-events-found-not-matching-number-of-events-displayed/m-p/296180#M165628</guid>
      <dc:creator>elliotproebstel</dc:creator>
      <dc:date>2018-01-03T18:50:18Z</dc:date>
    </item>
  </channel>
</rss>

