<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk counting issues/skills in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-counting-issues-skills/m-p/93373#M24045</link>
    <description>&lt;P&gt;OK. Hard to say without having more details. If these searches are truly identical and operate on a fixed timeframe for which no events are added, I'm at a loss. I'm pretty sure there's something going on with either of those assumptions though. You might want to have a look at the job inspector for each of the searches to see if/why they behave differently.&lt;/P&gt;</description>
    <pubDate>Sun, 14 Jul 2013 21:13:53 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2013-07-14T21:13:53Z</dc:date>
    <item>
      <title>Splunk counting issues/skills</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-counting-issues-skills/m-p/93368#M24040</link>
      <description>&lt;P&gt;Hey guys&lt;/P&gt;

&lt;P&gt;I am a bit puzzled by the counting skills of Splunk. &lt;/P&gt;

&lt;P&gt;I have a dashboard with 3 panels that will show a count by clientip in some access_logs, so when I fire the same search on the 3 panels with a time window of one month, I get different values in each ones of the counts of each panel. They only differ in small numbers, but I still find it very odd that Splunk is not getting to the same results every time....&lt;/P&gt;

&lt;P&gt;I'm using the geoip command on those searches...I am guessing that might something to do?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2013 04:14:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-counting-issues-skills/m-p/93368#M24040</guid>
      <dc:creator>asimagu</dc:creator>
      <dc:date>2013-07-12T04:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk counting issues/skills</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-counting-issues-skills/m-p/93369#M24041</link>
      <description>&lt;P&gt;Are you running these searches on an interval that includes the current time? Because in that case if you run 3 searches and you have data constantly flowing in, obviously the second search will get some new data that the first search didn't get...and same thing with the third search.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2013 07:22:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-counting-issues-skills/m-p/93369#M24041</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-07-12T07:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk counting issues/skills</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-counting-issues-skills/m-p/93370#M24042</link>
      <description>&lt;P&gt;I'm afraid not, it does not include current time. I am running those searches through the month of June&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jul 2013 20:44:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-counting-issues-skills/m-p/93370#M24042</guid>
      <dc:creator>asimagu</dc:creator>
      <dc:date>2013-07-14T20:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk counting issues/skills</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-counting-issues-skills/m-p/93371#M24043</link>
      <description>&lt;P&gt;OK. What's the difference between the 3 searches, since you're using 3 panels rather than just 1 I assume something's different at least?&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jul 2013 21:03:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-counting-issues-skills/m-p/93371#M24043</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-07-14T21:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk counting issues/skills</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-counting-issues-skills/m-p/93372#M24044</link>
      <description>&lt;P&gt;The idea of that dashboard was to make comparisons between different timeframes and different values of certain fields. I spotted some discrepancies between the same searches in two dashboards so I decided to run the same exact search in those 3 panels at the same time.... and surprise! I got 3 different results for the count of events: 1794, 1797, 1789 ..... so strange!&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jul 2013 21:10:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-counting-issues-skills/m-p/93372#M24044</guid>
      <dc:creator>asimagu</dc:creator>
      <dc:date>2013-07-14T21:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk counting issues/skills</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-counting-issues-skills/m-p/93373#M24045</link>
      <description>&lt;P&gt;OK. Hard to say without having more details. If these searches are truly identical and operate on a fixed timeframe for which no events are added, I'm at a loss. I'm pretty sure there's something going on with either of those assumptions though. You might want to have a look at the job inspector for each of the searches to see if/why they behave differently.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jul 2013 21:13:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-counting-issues-skills/m-p/93373#M24045</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-07-14T21:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk counting issues/skills</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-counting-issues-skills/m-p/93374#M24046</link>
      <description>&lt;P&gt;parent search:&lt;BR /&gt;
eventtype="pyme_page" status=200 | geoip clientip | search clientip_country_name="$country$" | fields clientip _time date_hour date_wday&lt;/P&gt;

&lt;P&gt;postprocess 1:&lt;BR /&gt;
stats count(clientip) | rangemap field=count(clientip) low=0-29 elevated=30-99 high=100-500 severe=501-10000 default=low&lt;/P&gt;

&lt;P&gt;and that is replicated 3 exact times in my dashboard, in each of the panels. I was lost and that's why I came here to ask, I'm really suspecting it has something to do with the geoip command...&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:20:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-counting-issues-skills/m-p/93374#M24046</guid>
      <dc:creator>asimagu</dc:creator>
      <dc:date>2020-09-28T14:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk counting issues/skills</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-counting-issues-skills/m-p/93375#M24047</link>
      <description>&lt;P&gt;I finally spotted the problem. It was the version of Firefox that I was using.... everything worked alright on Chrome&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2013 03:05:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-counting-issues-skills/m-p/93375#M24047</guid>
      <dc:creator>asimagu</dc:creator>
      <dc:date>2013-12-10T03:05:27Z</dc:date>
    </item>
  </channel>
</rss>

