<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: disapearing results in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/disapearing-results/m-p/19661#M3005</link>
    <description>&lt;P&gt;Can you post the actual search?&lt;/P&gt;</description>
    <pubDate>Tue, 30 Apr 2013 02:08:10 GMT</pubDate>
    <dc:creator>sideview</dc:creator>
    <dc:date>2013-04-30T02:08:10Z</dc:date>
    <item>
      <title>disapearing results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/disapearing-results/m-p/19660#M3004</link>
      <description>&lt;P&gt;I have a search that will show the results populating as it runs.  Then out of nowhere the results drop to 0 and the search just continues to run till finished.  I am just using a stats command so there are no commands that I am using like WHERE or anything else that would cause the results to drop to 0 if a condition is met.  The search does take quite a while to run, over a hour. Has anyone experience this before? I am on 4.3.5&lt;/P&gt;

&lt;P&gt;When i run the same search from another search head that has the same search peers the search finishes with all the results listed.  &lt;/P&gt;

&lt;P&gt;Could there be some type of dispatch limit that I am reaching? I have tried running this search on demand and as a saved search with the same results. &lt;/P&gt;

&lt;P&gt;I did notice that in the dispatch folder for this search that the results_preview.csv file will be there as the search runs and then as soon as the results drop to 0 the results_preview.csv file is gone.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:48:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/disapearing-results/m-p/19660#M3004</guid>
      <dc:creator>cramasta</dc:creator>
      <dc:date>2020-09-28T13:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: disapearing results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/disapearing-results/m-p/19661#M3005</link>
      <description>&lt;P&gt;Can you post the actual search?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2013 02:08:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/disapearing-results/m-p/19661#M3005</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2013-04-30T02:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: disapearing results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/disapearing-results/m-p/19662#M3006</link>
      <description>&lt;P&gt;Turns out there was a clean up script that someone had running which was periodically clearing out files from the dispatch directory. DOH!&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2013 20:30:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/disapearing-results/m-p/19662#M3006</guid>
      <dc:creator>cramasta</dc:creator>
      <dc:date>2013-04-30T20:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: disapearing results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/disapearing-results/m-p/19663#M3007</link>
      <description>&lt;P&gt;Yeah, that's a really bad idea.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2013 22:41:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/disapearing-results/m-p/19663#M3007</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2013-04-30T22:41:10Z</dc:date>
    </item>
  </channel>
</rss>

