<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inconsistency between Splunk api vs GUI search results. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Inconsistency-between-Splunk-api-vs-GUI-search-results/m-p/20659#M3265</link>
    <description>&lt;P&gt;Hello Nick, thanks for the reply. &lt;BR /&gt;
I am adding inspects of both searches if that can give us any clues. One from API and other from GUI, I don't see any differences in there in search string, the only difference is of providers. Which I don't understand why would it use different sources if the search is run on a single platform. Anyway the Rest API has more sources and less number of results (110k), and GUI has less sources still more results (375k). The username doesn't matter, it can be one user or different user, all get the same result. And no the sourcetype is never changed, timezones are also same. API will finish the search relatively quickly (less than 30 seconds) compared to GUI (about a minutes).&lt;/P&gt;

&lt;P&gt;Thanks! &lt;/P&gt;

&lt;P&gt;GUI Search - &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  `Search job properties

createTime  2011-06-01T07:01:16.000+00:00
cursorTime  2011-05-30T02:30:00.000+00:00
delegate    None
diskUsage   0
doneProgress    1.0
dropCount   0
eai:acl {'sharing': 'global', 'perms': {'read': ['user1'], 'write': ['user1']}, 'app': 'search', 'modifiable': 'true', 'can_write': 'true', 'owner': 'user1'}
earliestTime    2011-05-30T02:30:00.000+00:00
eventAvailableCount 10000
eventCount  375218
eventFieldCount 26
eventIsStreaming    True
eventIsTruncated    False
eventSearch search sourcetype="bankapp" earliest=05/30/2011:02:30:00 latest=05/30/2011:06:00:00
eventSorting    desc
isDone  True
isFailed    False
isFinalized False
isPaused    False
isPreviewEnabled    1
isRealTimeSearch    False
isSaved False
isSavedSearch   False
isZombie    False
keywords    earliest::05/30/2011:02:30:00 latest::05/30/2011:06:00:00 sourcetype::bankapp
label   None
latestTime  2011-05-30T06:00:00.000+00:00
messages    {'info': ['Your timerange was substituted based on your search string', '[splunk-tx-a1p] Your timerange was substituted based on your search string', '[splunk-tx-a2p] Your timerange was substituted based on your search string', '[splunk-tx-a3p] Your timerange was substituted based on your search string', '[splunk-nc-a2p] Your timerange was substituted based on your search string', '[splunk-nc-a3p] Your timerange was substituted based on your search string'], 'warn': ['Unable to distribute to peer named splunk-nc-a1p:8089 at uri &lt;A href="https://splunk-nc-a1p:8089" target="test_blank"&gt;https://splunk-nc-a1p:8089&lt;/A&gt; because peer has status = "Down".']}
modifiedTime    2011-06-01T07:18:56.000+00:00
performance {'dispatch.fetch': {'duration_secs': '20.058', 'invocations': '102'}, 'command.search.typer': {'duration_secs': '0.001', 'output_count': '0', 'input_count': '0', 'invocations': '1'}, 'dispatch.timeline': {'duration_secs': '47.979', 'invocations': '102'}, 'command.search.index': {'duration_secs': '0.001', 'invocations': '1'}, 'dispatch.preview': {'duration_secs': '0.101', 'invocations': '101'}, 'command.search.tags': {'duration_secs': '0.001', 'output_count': '0', 'input_count': '0', 'invocations': '1'}, 'command.search.filter': {'duration_secs': '0.001', 'invocations': '1'}, 'command.fields': {'duration_secs': '0.001', 'output_count': '0', 'input_count': '0', 'invocations': '1'}, 'command.search': {'duration_secs': '0.002', 'output_count': '0', 'input_count': '0', 'invocations': '2'}}
priority    5
remoteSearch    litsearch ( "sourcetype::bankapp" ) _time&amp;gt;=1306722600.000 _time&amp;lt;1306735200.000 | litsearch sourcetype="bankapp" _time&amp;gt;=1306722600.000 _time&amp;lt;1306735200.000 | fields keepcolorder=t * "*" "host" "index" "source" "sourcetype" "splunk_server"
reportSearch    None
request {'time_format': '%s.%Q', 'search': 'search sourcetype="bankapp" earliest=05/30/2011:02:30:00 latest=05/30/2011:06:00:00', 'required_field_list': '*', 'max_count': '10000', 'ui_dispatch_app': 'search', 'latest_time': None, 'status_buckets': '300', 'ui_dispatch_view': 'flashtimeline', 'earliest_time': None, 'auto_cancel': '100'}
resultCount 10000
resultIsStreaming   True
resultPreviewCount  10000
runDuration 73.526
scanCount   375218
search  search sourcetype="bankapp" earliest=05/30/2011:02:30:00 latest=05/30/2011:06:00:00
searchEarliestTime  1306722600.000000000
searchLatestTime    1306735200.000000000
searchProviders ['splunk-tx-a1p', 'splunk-tx-a2p', 'splunk-tx-a3p', 'splunk-nc-a2p', 'splunk-nc-a3p', 'splunkn-nc-a1p']
sid 1306911674.727
statusBuckets   300
ttl 555
Server info: Splunk 4.1.3, splunksearch, Wed Jun 1 07:19:41 2011; User: user1`
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Rest API  search -&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
Splunk Atom Feed: search sourcetype="bankapp" earliest=05/30/2011:02:30:00 latest=05/30/2011:06:00:00&lt;BR /&gt;
Updated: 2011-06-01T06:49:28.000+00:00 Splunk build:&lt;BR /&gt;
search sourcetype="bankapp" earliest=05/30/2011:02:30:00 latest=05/30/2011:06:00:00&lt;BR /&gt;
cursorTime  1970-01-01T00:00:00.000+00:00&lt;BR /&gt;
delegate    &lt;BR /&gt;
diskUsage   0&lt;BR /&gt;
doneProgress    1.00000&lt;BR /&gt;
dropCount   0&lt;BR /&gt;
eai:acl &lt;BR /&gt;
app search&lt;BR /&gt;
can_write   true&lt;BR /&gt;
modifiable  true&lt;BR /&gt;
owner   user3&lt;BR /&gt;
perms   &lt;BR /&gt;
read    &lt;BR /&gt;
user3&lt;BR /&gt;
write   &lt;BR /&gt;
user3&lt;BR /&gt;
sharing global&lt;BR /&gt;
earliestTime    2011-05-30T02:30:00.000+00:00&lt;BR /&gt;
eventAvailableCount 110902&lt;BR /&gt;
eventCount  110902&lt;BR /&gt;
eventFieldCount 0&lt;BR /&gt;
eventIsStreaming    1&lt;BR /&gt;
eventIsTruncated    0&lt;BR /&gt;
eventSearch search sourcetype="bankapp"  earliest=05/30/2011:02:30:00 latest=05/30/2011:06:00:00&lt;BR /&gt;
eventSorting    desc&lt;BR /&gt;
isDone  1&lt;BR /&gt;
isFailed    0&lt;BR /&gt;
isFinalized 0&lt;BR /&gt;
isPaused    0&lt;BR /&gt;
isPreviewEnabled    0&lt;BR /&gt;
isRealTimeSearch    0&lt;BR /&gt;
isSaved 0&lt;BR /&gt;
isSavedSearch   0&lt;BR /&gt;
isZombie    0&lt;BR /&gt;
keywords    earliest::05/30/2011:02:30:00 latest::05/30/2011:06:00:00 sourcetype::bankapp&lt;BR /&gt;
label   &lt;BR /&gt;
latestTime  2011-05-30T06:00:00.000+00:00&lt;BR /&gt;
messages    &lt;BR /&gt;
info    &lt;BR /&gt;
Your timerange was substituted based on your search string&lt;BR /&gt;
[splunk-nc-a1p] Your timerange was substituted based on your search string&lt;BR /&gt;
[splunk-nc-a2p] Your timerange was substituted based on your search string&lt;BR /&gt;
[splunk-nc-a3p] Your timerange was substituted based on your search string&lt;BR /&gt;
[splunk-tx-a1p] Your timerange was substituted based on your search string&lt;BR /&gt;
[splunk-tx-a2p] Your timerange was substituted based on your search string&lt;BR /&gt;
[splunk-tx-a3p] Your timerange was substituted based on your search string&lt;BR /&gt;
performance &lt;BR /&gt;
command.fields  &lt;BR /&gt;
duration_secs   0.001&lt;BR /&gt;
input_count 0&lt;BR /&gt;
invocations 1&lt;BR /&gt;
output_count    0&lt;BR /&gt;
command.search  &lt;BR /&gt;
duration_secs   0.002&lt;BR /&gt;
input_count 0&lt;BR /&gt;
invocations 2&lt;BR /&gt;
output_count    0&lt;BR /&gt;
command.search.filter   &lt;BR /&gt;
duration_secs   0.001&lt;BR /&gt;
invocations 1&lt;BR /&gt;
command.search.index    &lt;BR /&gt;
duration_secs   0.001&lt;BR /&gt;
invocations 1&lt;BR /&gt;
command.search.tags &lt;BR /&gt;
duration_secs   0.001&lt;BR /&gt;
input_count 0&lt;BR /&gt;
invocations 1&lt;BR /&gt;
output_count    0&lt;BR /&gt;
command.search.typer    &lt;BR /&gt;
duration_secs   0.001&lt;BR /&gt;
input_count 0&lt;BR /&gt;
invocations 1&lt;BR /&gt;
output_count    0&lt;BR /&gt;
dispatch.fetch  &lt;BR /&gt;
duration_secs   5.373&lt;BR /&gt;
invocations 71&lt;BR /&gt;
dispatch.timeline   &lt;BR /&gt;
duration_secs   3.267&lt;BR /&gt;
invocations 71&lt;BR /&gt;
priority    5&lt;BR /&gt;
remoteSearch    litsearch ( "sourcetype::bankapp" ) _time&amp;gt;=1306722600.000 _time&amp;lt;1306735200.000 | litsearch sourcetype="bankapp" _time&amp;gt;=1306722600.000 _time&amp;lt;1306735200.000 | fields  keepcolorder=t "host" "index" "source" "sourcetype" "splunk_server"&lt;BR /&gt;
reportSearch    &lt;BR /&gt;
request &lt;BR /&gt;
search  search sourcetype="bankapp"  earliest=05/30/2011:02:30:00 latest=05/30/2011:06:00:00&lt;BR /&gt;
resultCount 110902&lt;BR /&gt;
resultIsStreaming   1&lt;BR /&gt;
resultPreviewCount  110902&lt;BR /&gt;
runDuration 17.015000&lt;BR /&gt;
scanCount   110902&lt;BR /&gt;
searchEarliestTime  1306722600.000000000&lt;BR /&gt;
searchLatestTime    1306735200.000000000&lt;BR /&gt;
searchProviders &lt;BR /&gt;
splunk-nc-a1p&lt;BR /&gt;
splunk-nc-a2p&lt;BR /&gt;
splunk-nc-a3p&lt;BR /&gt;
splunk-tx-a1p&lt;BR /&gt;
splunk-tx-a2p&lt;BR /&gt;
splunk-tx-a3p&lt;BR /&gt;
splunkn-tx-a1p&lt;BR /&gt;
sid 1306910951.708&lt;BR /&gt;
statusBuckets   0&lt;BR /&gt;
ttl 574&lt;BR /&gt;
events - results - results_preview - timeline - summary - control:&lt;BR /&gt;
2011-06-01T06:49:28.000+00:00 | user3&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Jun 2011 08:05:05 GMT</pubDate>
    <dc:creator>user121</dc:creator>
    <dc:date>2011-06-01T08:05:05Z</dc:date>
    <item>
      <title>Inconsistency between Splunk api vs GUI search results.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Inconsistency-between-Splunk-api-vs-GUI-search-results/m-p/20657#M3263</link>
      <description>&lt;P&gt;Inconsistency between Splunk api vs GUI search results. &lt;BR /&gt;
I am using the Rest API. When I use a search language string for a search on Rest API, After isDone the search end points shows a number of results and matching events, resultCount, eventCount. But when I use the same exact search language string to do manual search on the GUI, I get a different number of matching events. &lt;BR /&gt;
Example "search earliest=xxx latest=yyy sourcetype=zzz" on Rest API returns 100,000 matching events, but using the same search string (without the 'search' keyword) on GUI returns 300,000 matching events. The difference is big. I am not specifying any other search options, I am 100% sure of that.&lt;/P&gt;

&lt;P&gt;Anybody know why is there such difference for a same search on Rest and GUI? &lt;/P&gt;

&lt;P&gt;Thanks &lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2011 05:52:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Inconsistency-between-Splunk-api-vs-GUI-search-results/m-p/20657#M3263</guid>
      <dc:creator>user121</dc:creator>
      <dc:date>2011-06-01T05:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistency between Splunk api vs GUI search results.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Inconsistency-between-Splunk-api-vs-GUI-search-results/m-p/20658#M3264</link>
      <description>&lt;P&gt;UPDATE:&lt;BR /&gt;&lt;BR /&gt;
in the end it's both quite simple and confusing.   When you're using the REST API, if you're interested in the count of events and nothing more,  you will have to tack on a " | stats count" on the end of your search.  And when the job is done you have to hit the /results endpoint, and retrieve the value of the count field.  Although the 'eventCount' property on the job looks like what you want,   it will actually NOT BE ACCURATE.  Once the job passes 100,000 events, and the search was submitted with the default of status_buckets=0, it knows that there is no point in continuing to run the search so it 'finalizes' the search.  Yes, you might argue that the eventCount itself proceeding towards an accurate number amounts to meaningful progress so why not continue the search anyway.    I guess the official answer is that properties on the job are really just meant to be internal debugging stuff, and for canonical answers you should use appropriate search language and get field values from the /results endpoints. &lt;/P&gt;

&lt;P&gt;Anyway, when you run the same search in the flashtimeline, the reason that search does not quietly autofinalize when it passes 100,000 events, is that the UI submits the search with status_buckets=300.  Whenever status_buckets is greater than 0,  that means splunk has to summarize the field results (into at least one bucket),  so in that case it doesnt let the search self-finalize and instead it runs to completion so that the summaries it's building will be accurate. &lt;/P&gt;

&lt;P&gt;ORIGINAL ANSWER: &lt;BR /&gt;&lt;BR /&gt;
There's definitely shouldn't be a difference in the results.   But there definitely is a difference in the arguments being used at some level, simply because the UI itself uses the REST API to dispatch its searches.  &lt;/P&gt;

&lt;P&gt;Unfortunately it's the POST that kicks off the jobs, otherwise the troubleshooting task would be very simple in that we could just go look in your splunkd_access log and read the arguments for ourselves. &lt;/P&gt;

&lt;P&gt;I dont have any answers but I have more questions. &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Are either the first events or the last events the same in both search results?  &lt;/P&gt;

&lt;P&gt;Maybe somehow the timerange is being interpreted differently.  If you go to 'inspect search job' in the UI or hit the jobs endpoint in the REST API, both jobs will have properties on them called earliestTime and latestTime.  These represent the absolute-time equivalents of the time arguments you specified.  Check that they are the same.  Incidentally it's not best practice to set your earliest and latest in the search string when you're using the rest API.  You can use the earliest and latest API args instead. &lt;/P&gt;

&lt;P&gt;How long do the searches take to complete?  It's possible that somehow a lower default threshold is being set to auto_finalize the search in the API.  &lt;/P&gt;

&lt;P&gt;Is there anything special about that sourcetype?  Was this sourcetype ever renamed? Does it happen with other sourcetypes as well? &lt;/P&gt;

&lt;P&gt;Incidentally how are you determining the eventCount for both searches?  &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:38:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Inconsistency-between-Splunk-api-vs-GUI-search-results/m-p/20658#M3264</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2020-09-28T09:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistency between Splunk api vs GUI search results.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Inconsistency-between-Splunk-api-vs-GUI-search-results/m-p/20659#M3265</link>
      <description>&lt;P&gt;Hello Nick, thanks for the reply. &lt;BR /&gt;
I am adding inspects of both searches if that can give us any clues. One from API and other from GUI, I don't see any differences in there in search string, the only difference is of providers. Which I don't understand why would it use different sources if the search is run on a single platform. Anyway the Rest API has more sources and less number of results (110k), and GUI has less sources still more results (375k). The username doesn't matter, it can be one user or different user, all get the same result. And no the sourcetype is never changed, timezones are also same. API will finish the search relatively quickly (less than 30 seconds) compared to GUI (about a minutes).&lt;/P&gt;

&lt;P&gt;Thanks! &lt;/P&gt;

&lt;P&gt;GUI Search - &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  `Search job properties

createTime  2011-06-01T07:01:16.000+00:00
cursorTime  2011-05-30T02:30:00.000+00:00
delegate    None
diskUsage   0
doneProgress    1.0
dropCount   0
eai:acl {'sharing': 'global', 'perms': {'read': ['user1'], 'write': ['user1']}, 'app': 'search', 'modifiable': 'true', 'can_write': 'true', 'owner': 'user1'}
earliestTime    2011-05-30T02:30:00.000+00:00
eventAvailableCount 10000
eventCount  375218
eventFieldCount 26
eventIsStreaming    True
eventIsTruncated    False
eventSearch search sourcetype="bankapp" earliest=05/30/2011:02:30:00 latest=05/30/2011:06:00:00
eventSorting    desc
isDone  True
isFailed    False
isFinalized False
isPaused    False
isPreviewEnabled    1
isRealTimeSearch    False
isSaved False
isSavedSearch   False
isZombie    False
keywords    earliest::05/30/2011:02:30:00 latest::05/30/2011:06:00:00 sourcetype::bankapp
label   None
latestTime  2011-05-30T06:00:00.000+00:00
messages    {'info': ['Your timerange was substituted based on your search string', '[splunk-tx-a1p] Your timerange was substituted based on your search string', '[splunk-tx-a2p] Your timerange was substituted based on your search string', '[splunk-tx-a3p] Your timerange was substituted based on your search string', '[splunk-nc-a2p] Your timerange was substituted based on your search string', '[splunk-nc-a3p] Your timerange was substituted based on your search string'], 'warn': ['Unable to distribute to peer named splunk-nc-a1p:8089 at uri &lt;A href="https://splunk-nc-a1p:8089" target="test_blank"&gt;https://splunk-nc-a1p:8089&lt;/A&gt; because peer has status = "Down".']}
modifiedTime    2011-06-01T07:18:56.000+00:00
performance {'dispatch.fetch': {'duration_secs': '20.058', 'invocations': '102'}, 'command.search.typer': {'duration_secs': '0.001', 'output_count': '0', 'input_count': '0', 'invocations': '1'}, 'dispatch.timeline': {'duration_secs': '47.979', 'invocations': '102'}, 'command.search.index': {'duration_secs': '0.001', 'invocations': '1'}, 'dispatch.preview': {'duration_secs': '0.101', 'invocations': '101'}, 'command.search.tags': {'duration_secs': '0.001', 'output_count': '0', 'input_count': '0', 'invocations': '1'}, 'command.search.filter': {'duration_secs': '0.001', 'invocations': '1'}, 'command.fields': {'duration_secs': '0.001', 'output_count': '0', 'input_count': '0', 'invocations': '1'}, 'command.search': {'duration_secs': '0.002', 'output_count': '0', 'input_count': '0', 'invocations': '2'}}
priority    5
remoteSearch    litsearch ( "sourcetype::bankapp" ) _time&amp;gt;=1306722600.000 _time&amp;lt;1306735200.000 | litsearch sourcetype="bankapp" _time&amp;gt;=1306722600.000 _time&amp;lt;1306735200.000 | fields keepcolorder=t * "*" "host" "index" "source" "sourcetype" "splunk_server"
reportSearch    None
request {'time_format': '%s.%Q', 'search': 'search sourcetype="bankapp" earliest=05/30/2011:02:30:00 latest=05/30/2011:06:00:00', 'required_field_list': '*', 'max_count': '10000', 'ui_dispatch_app': 'search', 'latest_time': None, 'status_buckets': '300', 'ui_dispatch_view': 'flashtimeline', 'earliest_time': None, 'auto_cancel': '100'}
resultCount 10000
resultIsStreaming   True
resultPreviewCount  10000
runDuration 73.526
scanCount   375218
search  search sourcetype="bankapp" earliest=05/30/2011:02:30:00 latest=05/30/2011:06:00:00
searchEarliestTime  1306722600.000000000
searchLatestTime    1306735200.000000000
searchProviders ['splunk-tx-a1p', 'splunk-tx-a2p', 'splunk-tx-a3p', 'splunk-nc-a2p', 'splunk-nc-a3p', 'splunkn-nc-a1p']
sid 1306911674.727
statusBuckets   300
ttl 555
Server info: Splunk 4.1.3, splunksearch, Wed Jun 1 07:19:41 2011; User: user1`
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Rest API  search -&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
Splunk Atom Feed: search sourcetype="bankapp" earliest=05/30/2011:02:30:00 latest=05/30/2011:06:00:00&lt;BR /&gt;
Updated: 2011-06-01T06:49:28.000+00:00 Splunk build:&lt;BR /&gt;
search sourcetype="bankapp" earliest=05/30/2011:02:30:00 latest=05/30/2011:06:00:00&lt;BR /&gt;
cursorTime  1970-01-01T00:00:00.000+00:00&lt;BR /&gt;
delegate    &lt;BR /&gt;
diskUsage   0&lt;BR /&gt;
doneProgress    1.00000&lt;BR /&gt;
dropCount   0&lt;BR /&gt;
eai:acl &lt;BR /&gt;
app search&lt;BR /&gt;
can_write   true&lt;BR /&gt;
modifiable  true&lt;BR /&gt;
owner   user3&lt;BR /&gt;
perms   &lt;BR /&gt;
read    &lt;BR /&gt;
user3&lt;BR /&gt;
write   &lt;BR /&gt;
user3&lt;BR /&gt;
sharing global&lt;BR /&gt;
earliestTime    2011-05-30T02:30:00.000+00:00&lt;BR /&gt;
eventAvailableCount 110902&lt;BR /&gt;
eventCount  110902&lt;BR /&gt;
eventFieldCount 0&lt;BR /&gt;
eventIsStreaming    1&lt;BR /&gt;
eventIsTruncated    0&lt;BR /&gt;
eventSearch search sourcetype="bankapp"  earliest=05/30/2011:02:30:00 latest=05/30/2011:06:00:00&lt;BR /&gt;
eventSorting    desc&lt;BR /&gt;
isDone  1&lt;BR /&gt;
isFailed    0&lt;BR /&gt;
isFinalized 0&lt;BR /&gt;
isPaused    0&lt;BR /&gt;
isPreviewEnabled    0&lt;BR /&gt;
isRealTimeSearch    0&lt;BR /&gt;
isSaved 0&lt;BR /&gt;
isSavedSearch   0&lt;BR /&gt;
isZombie    0&lt;BR /&gt;
keywords    earliest::05/30/2011:02:30:00 latest::05/30/2011:06:00:00 sourcetype::bankapp&lt;BR /&gt;
label   &lt;BR /&gt;
latestTime  2011-05-30T06:00:00.000+00:00&lt;BR /&gt;
messages    &lt;BR /&gt;
info    &lt;BR /&gt;
Your timerange was substituted based on your search string&lt;BR /&gt;
[splunk-nc-a1p] Your timerange was substituted based on your search string&lt;BR /&gt;
[splunk-nc-a2p] Your timerange was substituted based on your search string&lt;BR /&gt;
[splunk-nc-a3p] Your timerange was substituted based on your search string&lt;BR /&gt;
[splunk-tx-a1p] Your timerange was substituted based on your search string&lt;BR /&gt;
[splunk-tx-a2p] Your timerange was substituted based on your search string&lt;BR /&gt;
[splunk-tx-a3p] Your timerange was substituted based on your search string&lt;BR /&gt;
performance &lt;BR /&gt;
command.fields  &lt;BR /&gt;
duration_secs   0.001&lt;BR /&gt;
input_count 0&lt;BR /&gt;
invocations 1&lt;BR /&gt;
output_count    0&lt;BR /&gt;
command.search  &lt;BR /&gt;
duration_secs   0.002&lt;BR /&gt;
input_count 0&lt;BR /&gt;
invocations 2&lt;BR /&gt;
output_count    0&lt;BR /&gt;
command.search.filter   &lt;BR /&gt;
duration_secs   0.001&lt;BR /&gt;
invocations 1&lt;BR /&gt;
command.search.index    &lt;BR /&gt;
duration_secs   0.001&lt;BR /&gt;
invocations 1&lt;BR /&gt;
command.search.tags &lt;BR /&gt;
duration_secs   0.001&lt;BR /&gt;
input_count 0&lt;BR /&gt;
invocations 1&lt;BR /&gt;
output_count    0&lt;BR /&gt;
command.search.typer    &lt;BR /&gt;
duration_secs   0.001&lt;BR /&gt;
input_count 0&lt;BR /&gt;
invocations 1&lt;BR /&gt;
output_count    0&lt;BR /&gt;
dispatch.fetch  &lt;BR /&gt;
duration_secs   5.373&lt;BR /&gt;
invocations 71&lt;BR /&gt;
dispatch.timeline   &lt;BR /&gt;
duration_secs   3.267&lt;BR /&gt;
invocations 71&lt;BR /&gt;
priority    5&lt;BR /&gt;
remoteSearch    litsearch ( "sourcetype::bankapp" ) _time&amp;gt;=1306722600.000 _time&amp;lt;1306735200.000 | litsearch sourcetype="bankapp" _time&amp;gt;=1306722600.000 _time&amp;lt;1306735200.000 | fields  keepcolorder=t "host" "index" "source" "sourcetype" "splunk_server"&lt;BR /&gt;
reportSearch    &lt;BR /&gt;
request &lt;BR /&gt;
search  search sourcetype="bankapp"  earliest=05/30/2011:02:30:00 latest=05/30/2011:06:00:00&lt;BR /&gt;
resultCount 110902&lt;BR /&gt;
resultIsStreaming   1&lt;BR /&gt;
resultPreviewCount  110902&lt;BR /&gt;
runDuration 17.015000&lt;BR /&gt;
scanCount   110902&lt;BR /&gt;
searchEarliestTime  1306722600.000000000&lt;BR /&gt;
searchLatestTime    1306735200.000000000&lt;BR /&gt;
searchProviders &lt;BR /&gt;
splunk-nc-a1p&lt;BR /&gt;
splunk-nc-a2p&lt;BR /&gt;
splunk-nc-a3p&lt;BR /&gt;
splunk-tx-a1p&lt;BR /&gt;
splunk-tx-a2p&lt;BR /&gt;
splunk-tx-a3p&lt;BR /&gt;
splunkn-tx-a1p&lt;BR /&gt;
sid 1306910951.708&lt;BR /&gt;
statusBuckets   0&lt;BR /&gt;
ttl 574&lt;BR /&gt;
events - results - results_preview - timeline - summary - control:&lt;BR /&gt;
2011-06-01T06:49:28.000+00:00 | user3&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2011 08:05:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Inconsistency-between-Splunk-api-vs-GUI-search-results/m-p/20659#M3265</guid>
      <dc:creator>user121</dc:creator>
      <dc:date>2011-06-01T08:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistency between Splunk api vs GUI search results.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Inconsistency-between-Splunk-api-vs-GUI-search-results/m-p/20660#M3266</link>
      <description>&lt;P&gt;Got it. I found out what was going on and updated my answer. See above.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2011 21:37:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Inconsistency-between-Splunk-api-vs-GUI-search-results/m-p/20660#M3266</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2011-06-02T21:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistency between Splunk api vs GUI search results.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Inconsistency-between-Splunk-api-vs-GUI-search-results/m-p/20661#M3267</link>
      <description>&lt;P&gt;THANKS A LOT!!&lt;BR /&gt;
Just adding &lt;CODE&gt;status_buckets = integer&lt;/CODE&gt; to my API search query's post parameters solved the problem! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2011 10:11:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Inconsistency-between-Splunk-api-vs-GUI-search-results/m-p/20661#M3267</guid>
      <dc:creator>user121</dc:creator>
      <dc:date>2011-06-03T10:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistency between Splunk api vs GUI search results.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Inconsistency-between-Splunk-api-vs-GUI-search-results/m-p/20662#M3268</link>
      <description>&lt;P&gt;this is just summarizing my answer but if you add a "| stats count" onto the end of your REST search, and then when the job has finished, you make a separate request to the /results endpoint and retrieve the value of the 'count' field from the first row.  I know it seems complicated.  The other way is to submit your search with status_buckets set to 1, but then the search will run MUCH slower and do tons of work that you dont need.  It's FAR better to take the step into the world of the search language and start with " | stats count".&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2011 18:18:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Inconsistency-between-Splunk-api-vs-GUI-search-results/m-p/20662#M3268</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2011-06-03T18:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistency between Splunk api vs GUI search results.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Inconsistency-between-Splunk-api-vs-GUI-search-results/m-p/20663#M3269</link>
      <description>&lt;P&gt;I am also using the Splunk REST API to do summary indexing (adding a " | collect index=&lt;INDEX_NAME&gt;" at the end of my search.... Does what your saying, mean that when my search runs, and encounters more than 100,000 rows from which it is THEN to summarize and populate the SI with, that it will stop searching for events after 100,000 rows, and only summarize the first 100,000 into the SI???&lt;/INDEX_NAME&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2011 15:53:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Inconsistency-between-Splunk-api-vs-GUI-search-results/m-p/20663#M3269</guid>
      <dc:creator>jdunlea_splunk</dc:creator>
      <dc:date>2011-12-14T15:53:33Z</dc:date>
    </item>
  </channel>
</rss>

