<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic .csv file does not contain all data in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/csv-file-does-not-contain-all-data/m-p/78869#M19933</link>
    <description>&lt;P&gt;I have set up a scheduled report which select current month data.&lt;/P&gt;

&lt;P&gt;I have set up the report to be sent as a .csv file to a number of e-mail adresses.
The same report is also included in a DashBoard as a table.&lt;/P&gt;

&lt;P&gt;In the start of the month the number of data is same in the .csv file and in the DashBoard&lt;/P&gt;

&lt;P&gt;But in the middle of the month the .csv file does not contain ALL data - whereas the report shown in the DashBoard do contain all data.&lt;/P&gt;

&lt;P&gt;Has somebody else experienced this? - and do you have an explanation - and hopefully a solution?&lt;/P&gt;

&lt;P&gt;The setup is as follows:&lt;/P&gt;

&lt;P&gt;Schedule type= Basic&lt;/P&gt;

&lt;P&gt;Run every day at midnight&lt;/P&gt;

&lt;P&gt;Perform actions: always&lt;/P&gt;

&lt;P&gt;Alert actions: Send E-mail&lt;/P&gt;

&lt;P&gt;Include results in e-mail&lt;/P&gt;</description>
    <pubDate>Mon, 11 Apr 2011 19:19:54 GMT</pubDate>
    <dc:creator>JYTTEJ</dc:creator>
    <dc:date>2011-04-11T19:19:54Z</dc:date>
    <item>
      <title>.csv file does not contain all data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/csv-file-does-not-contain-all-data/m-p/78869#M19933</link>
      <description>&lt;P&gt;I have set up a scheduled report which select current month data.&lt;/P&gt;

&lt;P&gt;I have set up the report to be sent as a .csv file to a number of e-mail adresses.
The same report is also included in a DashBoard as a table.&lt;/P&gt;

&lt;P&gt;In the start of the month the number of data is same in the .csv file and in the DashBoard&lt;/P&gt;

&lt;P&gt;But in the middle of the month the .csv file does not contain ALL data - whereas the report shown in the DashBoard do contain all data.&lt;/P&gt;

&lt;P&gt;Has somebody else experienced this? - and do you have an explanation - and hopefully a solution?&lt;/P&gt;

&lt;P&gt;The setup is as follows:&lt;/P&gt;

&lt;P&gt;Schedule type= Basic&lt;/P&gt;

&lt;P&gt;Run every day at midnight&lt;/P&gt;

&lt;P&gt;Perform actions: always&lt;/P&gt;

&lt;P&gt;Alert actions: Send E-mail&lt;/P&gt;

&lt;P&gt;Include results in e-mail&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2011 19:19:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/csv-file-does-not-contain-all-data/m-p/78869#M19933</guid>
      <dc:creator>JYTTEJ</dc:creator>
      <dc:date>2011-04-11T19:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: .csv file does not contain all data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/csv-file-does-not-contain-all-data/m-p/78870#M19934</link>
      <description>&lt;P&gt;There could be a number of reasons why a report generated by the "scheduler" (alerts) vs. a dashboard, but the most common are related to permissions and timestamping. If timestamps (_time) in your data are being extracted incorrectly, or with great enough drift you could see discrepencies between scheduled and dashboard based searches.&lt;/P&gt;

&lt;P&gt;Without having some specifics around your configurations this is a bit tricky to answer.  There is also some weirdness related to why this works part of the month, but not in the middle.... I would recommend opening a case with support if this is still an issue for you.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2011 19:38:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/csv-file-does-not-contain-all-data/m-p/78870#M19934</guid>
      <dc:creator>hazekamp</dc:creator>
      <dc:date>2011-04-15T19:38:36Z</dc:date>
    </item>
  </channel>
</rss>

