<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Same search returns different results each time it is run. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/595564#M207276</link>
    <description>&lt;P&gt;Just to be on the safe side.&lt;/P&gt;&lt;P&gt;Does the number increase or is it "randomly fluctuating"?&lt;/P&gt;&lt;P&gt;Did you try limiting by _index_earliest and _index_latest and see if the number of results is constant?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Apr 2022 11:56:12 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2022-04-27T11:56:12Z</dc:date>
    <item>
      <title>Same search returns different results each time it is run?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/581451#M202569</link>
      <description>&lt;P&gt;I have this weird issue where the same exact search, run for a same exact period returns different number of events each time it is run.&lt;BR /&gt;Thus, rendering all attempts for accurate reporting obsolete.&lt;BR /&gt;It doesn't matter the type of search, for instance, if it has some statistics or it's just plain search - same searches return different results.&lt;BR /&gt;We've checked all the usual stuff - event sampling is turned off, indexing time is OK and it's not lagging, so no skewing of the results can come from this.&lt;BR /&gt;Searches are run directly against indexes, no data models are involved and search logs for the searches are identical for the runs compared to each other.&lt;BR /&gt;What we discovered for sure is, that this issue affects only indexes that are stored in an S3 Storage. Locally kept indexes are fine and do not have this issue.&lt;BR /&gt;The S3 storage was tested, it is configured correctly, there are no network disruptions, there are no errors in the logs concerning it, there's nothing that could hint a problem.&lt;BR /&gt;Yet, the problem remains.&lt;/P&gt;
&lt;P&gt;Any idea what may be causing this?&lt;/P&gt;
&lt;P&gt;Attaching a screenshot just for visualization, and here's the search for which it was made:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="qualys" sourcetype="qualys:hostDetection" PATCHABLE="YES" NETBIOS="*"​&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 15:21:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/581451#M202569</guid>
      <dc:creator>mmarinov</dc:creator>
      <dc:date>2023-03-16T15:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Same search returns different results each time it is run.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/594764#M207008</link>
      <description>&lt;P&gt;Hi mmarinov,&lt;/P&gt;&lt;P&gt;I am facing same issue. Did you find anything to resolve it. Thanks in Advance&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 23:39:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/594764#M207008</guid>
      <dc:creator>sindhi</dc:creator>
      <dc:date>2022-04-21T23:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: Same search returns different results each time it is run.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/594835#M207018</link>
      <description>&lt;P&gt;First thing to check in such case would be to see the job inspect window for any differences. And see the job log for any warnings/errors.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 11:30:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/594835#M207018</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-04-22T11:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: Same search returns different results each time it is run.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/594867#M207021</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;have you both S3 as a SmartStore in splunk or some other S3-storage? Is this on AWS S3 or some other S3 implementation e.g. in OnPrem?&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 12:51:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/594867#M207021</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-04-22T12:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: Same search returns different results each time it is run.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/595536#M207264</link>
      <description>&lt;P&gt;Hi Sindhi,&lt;BR /&gt;&lt;BR /&gt;No resolution as of now, unfortunately.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 08:34:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/595536#M207264</guid>
      <dc:creator>mmarinov</dc:creator>
      <dc:date>2022-04-27T08:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: Same search returns different results each time it is run.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/595537#M207265</link>
      <description>&lt;P&gt;S3 SmartStore is used and the Splunk machines are on AWS EC2 instances.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 08:37:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/595537#M207265</guid>
      <dc:creator>mmarinov</dc:creator>
      <dc:date>2022-04-27T08:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: Same search returns different results each time it is run.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/595538#M207266</link>
      <description>&lt;P&gt;As stated in the original post, the job inspector returns basically identical information for the runs.&lt;BR /&gt;The only thing that is different are the execution times, which obviously cannot be identical.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 08:39:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/595538#M207266</guid>
      <dc:creator>mmarinov</dc:creator>
      <dc:date>2022-04-27T08:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: Same search returns different results each time it is run.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/595548#M207268</link>
      <description>&lt;P&gt;Have you looked from MC how cacheing is working or are there continuously need to get those from S3 instead of use cached version?&lt;/P&gt;&lt;P&gt;Can you also give some specification what you environment is looking and which kind of queries there are running (is those limited e.g. last 7d or all time etc.)&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 10:12:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/595548#M207268</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-04-27T10:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: Same search returns different results each time it is run.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/595561#M207275</link>
      <description>&lt;P&gt;The deployment is as follows:&lt;BR /&gt;1. Indexer cluster with 3 indexers&lt;/P&gt;&lt;P&gt;2. Cluster master node which is also a DMC&lt;/P&gt;&lt;P&gt;3. Search head with Enterprise Security&lt;/P&gt;&lt;P&gt;4. Deployment server&lt;/P&gt;&lt;P&gt;5. Heavy forwarder&lt;/P&gt;&lt;P&gt;6. Numerous UFs.&lt;BR /&gt;The deployment is on AWS EC2 instances.&lt;BR /&gt;&lt;BR /&gt;The type of query run makes no difference as stated in the original post.&lt;BR /&gt;I've tested now with the one from the original post, and monitored the S3 cache, check the screenshot.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 11:24:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/595561#M207275</guid>
      <dc:creator>mmarinov</dc:creator>
      <dc:date>2022-04-27T11:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: Same search returns different results each time it is run.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/595564#M207276</link>
      <description>&lt;P&gt;Just to be on the safe side.&lt;/P&gt;&lt;P&gt;Does the number increase or is it "randomly fluctuating"?&lt;/P&gt;&lt;P&gt;Did you try limiting by _index_earliest and _index_latest and see if the number of results is constant?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 11:56:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/595564#M207276</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-04-27T11:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: Same search returns different results each time it is run.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/595567#M207278</link>
      <description>&lt;P&gt;It fluctuates.&lt;BR /&gt;Limiting with _index_earliest and _index_latest has no effect, the number of events still fluctuates.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 12:07:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/595567#M207278</guid>
      <dc:creator>mmarinov</dc:creator>
      <dc:date>2022-04-27T12:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: Same search returns different results each time it is run.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/634746#M220521</link>
      <description>&lt;P&gt;I do realize this is an old post, however, I had the same issue of slight fluctuations in search results. During the course of examining this issue, I stumbled upon this yet unanswered question.&lt;BR /&gt;&lt;BR /&gt;In my search query, I use the perc() function. Its&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SCS/current/SearchReference/Aggregatefunctions#perc.28.26lt.3Bvalue.26gt.3B.2C.26lt.3Bpercentile.26gt.3B.29" target="_blank" rel="noopener"&gt;documentation&lt;/A&gt; says the following:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;The&amp;nbsp;perc&amp;nbsp;and&amp;nbsp;upperperc&amp;nbsp;functions give &lt;STRONG&gt;approximate&lt;/STRONG&gt; values for the integer percentile requested. The approximation algorithm that is used, which is based on dynamic compression of a radix tree, provides a strict bound of the actual value for any percentile.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This means, sometimes it might be perc50.3, in the next run perc49.6, etc.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;In my case, this was the cause for the fluctuations I observed. Once I swapped it for a function like avg(), search results were steady.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 09:23:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Same-search-returns-different-results-each-time-it-is-run/m-p/634746#M220521</guid>
      <dc:creator>Gabriel</dc:creator>
      <dc:date>2023-03-16T09:23:37Z</dc:date>
    </item>
  </channel>
</rss>

