<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inconsistent results in Splunk in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Has-anyone-else-got-inconsistent-results-in-Splunk/m-p/620350#M215646</link>
    <description>&lt;P&gt;In what way are they different?&lt;/P&gt;&lt;P&gt;Have a look at the job inspector to see how many events are processed at each stage.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Nov 2022 22:34:19 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2022-11-09T22:34:19Z</dc:date>
    <item>
      <title>Has anyone else got inconsistent results in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Has-anyone-else-got-inconsistent-results-in-Splunk/m-p/620346#M215643</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;on our Splunk instance I have set a report using a time chart with a span of 1h and time frame of a day and the report is scheduled to run every hour however each time the report runs it shows different results. Just wondered if anyone has seen this before?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;joe&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 15:27:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Has-anyone-else-got-inconsistent-results-in-Splunk/m-p/620346#M215643</guid>
      <dc:creator>joe06031990</dc:creator>
      <dc:date>2022-11-10T15:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent results in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Has-anyone-else-got-inconsistent-results-in-Splunk/m-p/620350#M215646</link>
      <description>&lt;P&gt;In what way are they different?&lt;/P&gt;&lt;P&gt;Have a look at the job inspector to see how many events are processed at each stage.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 22:34:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Has-anyone-else-got-inconsistent-results-in-Splunk/m-p/620350#M215646</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-11-09T22:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent results in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Has-anyone-else-got-inconsistent-results-in-Splunk/m-p/620351#M215647</link>
      <description>&lt;P&gt;What is your time range set to, i.e. what is the exact earliest/latest in the search definition.&lt;/P&gt;&lt;P&gt;If you have your 'end' time as now, then it will search up to now, so naturally each hour will have different results.&lt;/P&gt;&lt;P&gt;When you say time frame of a day, do you mean 24h.&lt;/P&gt;&lt;P&gt;Can you expand on what you mean by 'different results'. In what way?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 22:35:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Has-anyone-else-got-inconsistent-results-in-Splunk/m-p/620351#M215647</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-11-09T22:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent results in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Has-anyone-else-got-inconsistent-results-in-Splunk/m-p/620354#M215650</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;the timeframe is set to today and the span in the time chart is 1 hour.&lt;/P&gt;&lt;P&gt;sometime the volume is lower or higher from the same hour.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 22:45:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Has-anyone-else-got-inconsistent-results-in-Splunk/m-p/620354#M215650</guid>
      <dc:creator>joe06031990</dc:creator>
      <dc:date>2022-11-09T22:45:37Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent results in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Has-anyone-else-got-inconsistent-results-in-Splunk/m-p/620356#M215651</link>
      <description>&lt;P&gt;So, at 10am it runs it gives 10 values for the first 10 hours and at 11 am you have 11 values, and are you saying that ANY of the first 10 can have different values or just the value for 10am?&lt;/P&gt;&lt;P&gt;What is the 'ending' time of the search in 'Today'? Is it now or&amp;nbsp;@h&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it's now, it will be somewhat vague, as it may not contain events that are being indexed at that time, or events that maybe arrive one or two minutes after the search has run, but which have slightly earlier times.&lt;/P&gt;&lt;P&gt;One way to see if you have event 'lag' is to look at _indextime field to see how much difference there is between that and _time.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If _time is some time before _indextime, you have lag&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 22:56:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Has-anyone-else-got-inconsistent-results-in-Splunk/m-p/620356#M215651</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-11-09T22:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent results in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Has-anyone-else-got-inconsistent-results-in-Splunk/m-p/620677#M215764</link>
      <description>&lt;P&gt;Looks like there was a fault with two of the search head nodes.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Nov 2022 10:49:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Has-anyone-else-got-inconsistent-results-in-Splunk/m-p/620677#M215764</guid>
      <dc:creator>joe06031990</dc:creator>
      <dc:date>2022-11-13T10:49:41Z</dc:date>
    </item>
  </channel>
</rss>

