<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Results are missing from this search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Results-are-missing-from-this-search/m-p/326593#M166158</link>
    <description>&lt;P&gt;@bj6192, would the following query work for you?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index="indexa" OR index="indexb") sourcetype="sourceA" user=*
| fields _time user
| stats max(_time) as _time by user
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Based on your query, both indexa and indexb have sourcetype sourceA containing user info. Is this correct?&lt;BR /&gt;
What is the time span you are using, how do the result look if you reduce the timespan to say 1 hour or 15 min?&lt;/P&gt;</description>
    <pubDate>Fri, 08 Sep 2017 09:24:13 GMT</pubDate>
    <dc:creator>niketn</dc:creator>
    <dc:date>2017-09-08T09:24:13Z</dc:date>
    <item>
      <title>Results are missing from this search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Results-are-missing-from-this-search/m-p/326592#M166157</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I use the below search to get the row with max value;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index="indexa" OR index="indexb") sourcetype="sourceA"  | table _time,money,user | eventstats max(_time) as mtime by user |where _time=mtime
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;but some user can not find in result. And When I add user in below search, it exists in result.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index="indexa" OR index="indexb") sourcetype="sourceA"  user="XXX" | table _time,money,user | eventstats max(_time) as mtime by user |where _time=mtime
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;How can I know what different in above search? Thanks&lt;BR /&gt;
ps.above search has 1 million row in first phase and the final result should has 220000 row output&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 06:49:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Results-are-missing-from-this-search/m-p/326592#M166157</guid>
      <dc:creator>bj6192</dc:creator>
      <dc:date>2017-09-08T06:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: Results are missing from this search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Results-are-missing-from-this-search/m-p/326593#M166158</link>
      <description>&lt;P&gt;@bj6192, would the following query work for you?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index="indexa" OR index="indexb") sourcetype="sourceA" user=*
| fields _time user
| stats max(_time) as _time by user
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Based on your query, both indexa and indexb have sourcetype sourceA containing user info. Is this correct?&lt;BR /&gt;
What is the time span you are using, how do the result look if you reduce the timespan to say 1 hour or 15 min?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 09:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Results-are-missing-from-this-search/m-p/326593#M166158</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-09-08T09:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Results are missing from this search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Results-are-missing-from-this-search/m-p/326594#M166159</link>
      <description>&lt;P&gt;Updated with feedback from @woodcock - &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index="indexa" OR index="indexb") sourcetype="sourceA" 
| fields money,user 
| rename _time as time
| fields - _*
| rename time as _time
| dedup user
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Everything before the &lt;CODE&gt;dedup&lt;/CODE&gt; will run on the indexers, leaving only three fields to be transmitted to the search head, at which point the records are collated in descending &lt;CODE&gt;_time&lt;/CODE&gt; order and due to the &lt;CODE&gt;dedup&lt;/CODE&gt; command, only the latest record for each &lt;CODE&gt;user&lt;/CODE&gt; will be retained. &lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;I believe you are just running out of time &lt;EM&gt;(updated - time and/or RAM).&lt;/EM&gt;  Try this...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index="indexa" OR index="indexb") sourcetype="sourceA" 
| fields money,user 
| eventstats max(_time) as mtime by user 
| where _time=mtime
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Explanation - &lt;CODE&gt;fields&lt;/CODE&gt; is a distributed streaming command, &lt;CODE&gt;table&lt;/CODE&gt; is not.  Because table has some aggregate effects (limiting the total number of records, for example) it cannot run at the individual indexers.  The table command requires ALL the data be held and transmitted to the search head, where the aggregate effects can be effected. &lt;/P&gt;

&lt;P&gt;&lt;EM&gt;(owww - did I really just type that sentence? ...let's pretend I typed "where the search head can make the aggregate effects happen.")&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;The &lt;CODE&gt;fields&lt;/CODE&gt; command will strip out the unneeded fields, streamlining the process so that it should run faster and require less resources.  Hopefully, that will make your user information  reappear.&lt;/P&gt;

&lt;P&gt;After you get through testing that, try this... &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index="indexa" OR index="indexb") sourcetype="sourceA" 
| fields money,user 
| dedup user
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It should achieve the same result slightly faster.  &lt;CODE&gt;dedup&lt;/CODE&gt; keeps the first event, and events are returned with the latest first, so a simple &lt;CODE&gt;dedup&lt;/CODE&gt; on user should get you the latest records for each. &lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 13:48:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Results-are-missing-from-this-search/m-p/326594#M166159</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-09-08T13:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: Results are missing from this search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Results-are-missing-from-this-search/m-p/326595#M166160</link>
      <description>&lt;P&gt;Your problem is the use of the &lt;CODE&gt;table&lt;/CODE&gt; command, which is a &lt;CODE&gt;finalizing&lt;/CODE&gt; command (or something like that).  It has the disastrous effect of ceasing all efficient map-reduction and sending the intermediate results as-is to the search head.  When you limit this result set by adding &lt;CODE&gt;user="XXX"&lt;/CODE&gt; it just so happens that you have reduced your totally absurd amount of intermediate results into a just-barely-manageable amount (maybe) so you don't run out of RAM on your search head (there is probably a log somewhere in &lt;CODE&gt;index=_*&lt;/CODE&gt; that says your search blew up the RAM) and the rest of your pipeline has at least a partially complete result set to work on.&lt;/P&gt;

&lt;P&gt;The Pro-Tip here is: Always use &lt;CODE&gt;fields&lt;/CODE&gt;, never use &lt;CODE&gt;table&lt;/CODE&gt;.  Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index="indexa" OR index="indexb") sourcetype="sourceA"
| fields _time money user
| rename _time AS time
| fields - _*
| eventstats max(time) as mtime by user
| where time=mtime
| convert ctime(*time)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 09 Sep 2017 16:27:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Results-are-missing-from-this-search/m-p/326595#M166160</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-09-09T16:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: Results are missing from this search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Results-are-missing-from-this-search/m-p/326596#M166161</link>
      <description>&lt;P&gt;I like my explanation better but I didn't even look at what the overall search was trying to do and @DalJeanis has a better answer: &lt;CODE&gt;dedup&lt;/CODE&gt;.  I stopped reading his at first when he wrote "running out of time" because I knew that you were actually "running out of RAM".  But really, it could be either.  In the end, the root cause is the same: &lt;CODE&gt;table&lt;/CODE&gt;.  My search is still useful for others that are doing something that doesn't reduce down to &lt;CODE&gt;dedup&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2017 16:31:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Results-are-missing-from-this-search/m-p/326596#M166161</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-09-09T16:31:51Z</dc:date>
    </item>
  </channel>
</rss>

