<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are search results different when running a search in the Search app versus a dashboard panel? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/646507#M223774</link>
    <description>&lt;P&gt;Super helpful checklist, thanks!&amp;nbsp; Also will include a link to this answer as base queries with non-transforming results have boundary limits. I think if you're getting inconsistent results its because you're over a limit.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Post-processing-gives-incorrect-results/m-p/522520" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/Post-processing-gives-incorrect-results/m-p/522520&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 10 Jun 2023 15:59:18 GMT</pubDate>
    <dc:creator>lmonahan</dc:creator>
    <dc:date>2023-06-10T15:59:18Z</dc:date>
    <item>
      <title>Why are search results different when running a search in the Search app versus a dashboard panel?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/227888#M67304</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a search as a dashboard panel.&lt;/P&gt;

&lt;P&gt;When I execute the search on the dashboard, the result is incorrect.&lt;/P&gt;

&lt;P&gt;What's interesting is:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;If I refresh the panel, the result is still incorrect&lt;/LI&gt;
&lt;LI&gt;when I 'open the search' from the dashboard panel, it's still incorrect&lt;/LI&gt;
&lt;LI&gt;When hit the search button &lt;EM&gt;after&lt;/EM&gt; the 'open the search' the result is correct.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Unfortunately, I can't post up the search.&lt;/P&gt;

&lt;P&gt;Notes:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;At no stage was the search changed&lt;/LI&gt;
&lt;LI&gt;The time selector was not changed&lt;/LI&gt;
&lt;LI&gt;The search was working in Splunk &amp;lt;6.3.0&lt;/LI&gt;
&lt;LI&gt;If I dissect the search, the individual components return the expected result&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I'd be interested as to what I can do to check to see where the problem could be.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2015 12:07:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/227888#M67304</guid>
      <dc:creator>splunked38</dc:creator>
      <dc:date>2015-11-16T12:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why are search results different when running a search in the Search app versus a dashboard panel?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/227889#M67305</link>
      <description>&lt;P&gt;Are you using sub-search? If the sub-search reaches the limit, it will return 0 results, thereby affecting the results of the main search.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2015 13:52:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/227889#M67305</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2015-11-16T13:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why are search results different when running a search in the Search app versus a dashboard panel?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/227890#M67306</link>
      <description>&lt;P&gt;ok, that's understandable&lt;/P&gt;

&lt;P&gt;however, the search string returns the correct result when I manually copy and paste it into search.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2015 14:02:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/227890#M67306</guid>
      <dc:creator>splunked38</dc:creator>
      <dc:date>2015-11-16T14:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why are search results different when running a search in the Search app versus a dashboard panel?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/227891#M67307</link>
      <description>&lt;P&gt;I'm very new to Splunk (so my answer may be stupid) - but the first thing coming to my mind is the app context. Is the normal search maybe performed in another app? Do you have anything configured, like transforms combined with auto lookups which affect your search in any way?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2015 14:15:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/227891#M67307</guid>
      <dc:creator>Sebastian2</dc:creator>
      <dc:date>2015-11-16T14:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why are search results different when running a search in the Search app versus a dashboard panel?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/227892#M67308</link>
      <description>&lt;P&gt;I've 'narrowed down' the problem:&lt;BR /&gt;
the search in the dashboard panel looks like this:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;search xxx | stats count(Name) as search1&lt;BR /&gt;
| eval search2=[search yyy  | stats count(Name) as search2| rename search2 as query]&lt;BR /&gt;
| table search1, search2&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;search1 is ok, search2 produces the wrong result but if I did this in the dashboard panel:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;search yyy  | stats count(Name) as search2 | table search2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The correct result comes up.&lt;/P&gt;

&lt;P&gt;Just to re-iterate:&lt;BR /&gt;
if I go to the dashboard panel, hit 'open in search', the panel search will appear, I hit 'search', and the correct result appears. Because of this, I'm leaning away from the fact that the syntax is the issue. Something about the way the dash executes the search provides incorrect results.&lt;/P&gt;

&lt;P&gt;Before you ask, the reason why I need the two searches in the one dash is because I'm trying to get a percentage from the two searches:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;search xxx | stats count(Name) as search1&lt;BR /&gt;
| eval search2=[search yyy  | stats count(Name) as search2| rename search2 as query]&lt;BR /&gt;
| eval percent=round((search2/search1)*100,2).%&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2015 14:31:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/227892#M67308</guid>
      <dc:creator>splunked38</dc:creator>
      <dc:date>2015-11-16T14:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why are search results different when running a search in the Search app versus a dashboard panel?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/227893#M67309</link>
      <description>&lt;P&gt;If you look at the job inspector after you run the search in the main search window (after it returns results successfully), is there anything re: results being truncated? If there is, that is the reason dashboard results are inaccurate. &lt;/P&gt;

&lt;P&gt;Something else to look for, when you hit "open in search" in dashboard panel, BEFORE you hit the search button, do you see the results? Go look at the "normalizedSearch" in the job inspector window. Does that look correct?&lt;/P&gt;

&lt;P&gt;One more place to check - Run the search in dashboard and search window in quick successing. Go to "Activity-&amp;gt;Jobs. Compare the Events count from all 4 activities listed (2 for main search, 2 for subsearch). Are they the same? &lt;/P&gt;

&lt;P&gt;In my experience, if the result for a sub-search is  truncated, the results in dashboard is not the same as what you see in the main search window. Don't know why, just seen this happen.&lt;/P&gt;

&lt;P&gt;The other thing to verify is permissions and app context... do those look correct?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2015 14:59:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/227893#M67309</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2015-11-16T14:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why are search results different when running a search in the Search app versus a dashboard panel?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/227894#M67310</link>
      <description>&lt;P&gt;I compared the normalised searches between the two and they are both the same.&lt;/P&gt;

&lt;P&gt;Both the 'good' and the 'bad' search are truncated.&lt;/P&gt;

&lt;P&gt;Perms and app context are both accessible within the application.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2015 15:26:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/227894#M67310</guid>
      <dc:creator>splunked38</dc:creator>
      <dc:date>2015-11-16T15:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why are search results different when running a search in the Search app versus a dashboard panel?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/227895#M67311</link>
      <description>&lt;P&gt;Nope, dash is in search.&lt;/P&gt;

&lt;P&gt;If it was app context, why would the second attempt in search be different, I would expect it to be the same&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2015 11:38:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/227895#M67311</guid>
      <dc:creator>splunked38</dc:creator>
      <dc:date>2015-11-17T11:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why are search results different when running a search in the Search app versus a dashboard panel?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/646507#M223774</link>
      <description>&lt;P&gt;Super helpful checklist, thanks!&amp;nbsp; Also will include a link to this answer as base queries with non-transforming results have boundary limits. I think if you're getting inconsistent results its because you're over a limit.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Post-processing-gives-incorrect-results/m-p/522520" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/Post-processing-gives-incorrect-results/m-p/522520&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jun 2023 15:59:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-search-results-different-when-running-a-search-in-the/m-p/646507#M223774</guid>
      <dc:creator>lmonahan</dc:creator>
      <dc:date>2023-06-10T15:59:18Z</dc:date>
    </item>
  </channel>
</rss>

