<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why search results adds up when source is modified? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145818#M40679</link>
    <description>&lt;P&gt;To answer this question, I have done the steps like follow:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;First time, i created a index and i indexed  a csv file with that index.  When I start search  by putting “index=test1” in search bar, the result give me 3 events:&lt;/P&gt;

&lt;P&gt;9/15/14 &lt;BR /&gt;
10:52:20.411 AM &lt;BR /&gt;
8750321,"*ALL",JPD910,"11484/6788",UNKNOWN,"Mon Sep 15 10:52:20.411000","IPCMISC.C299&lt;BR /&gt;
    State information for process 10036, User=8750321, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP06, Version=LIS0001, Thread ID=9280, Thread Name=WRK:8750321_09D55650_P5542319."&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;

&lt;P&gt;9/13/14 &lt;BR /&gt;
3:28:27.380 PM&lt;BR /&gt;&lt;BR /&gt;
6635103,"*ALL",JPD910,"2664/14920",UNKNOWN,"Sat Sep 13 15:28:27.380002","IPCMISC.C299&lt;BR /&gt;
    State information for process 7764, User=6635103, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP07, Version=LIS0001, Thread ID=12632, Thread Name=WRK:Starting jdeCallObject."&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;

&lt;P&gt;9/11/14 &lt;BR /&gt;
12:59:54.203 PM &lt;BR /&gt;
6107085,"*ALL",JPD910,"12760/14360",UNKNOWN,"Thu Sep 11 12:59:54.203001","IPCMISC.C299&lt;BR /&gt;
    State information for process 10784, User=6107085, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP04, Version=LIS0001, Thread ID=13536, Thread Name=WRK:Starting jdeCallObject."&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Second time, in by editing this csv file, I make a change of first value of first event like this:&lt;BR /&gt;
8750321 its become 8750999. &lt;BR /&gt;
When I re-indexed the same file with another index which I created and name it test2, the same search give me results like follow with 6 events:&lt;/P&gt;

&lt;P&gt;9/15/14 &lt;BR /&gt;
10:52:20.411 AM &lt;BR /&gt;
"   State information for process 10036, User=8750321, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP06, Version=LIS0001, Thread ID=9280, Thread Name=WRK:8750321_09D55650_P5542319."""&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;

&lt;P&gt;9/15/14 &lt;BR /&gt;
10:52:20.411 AM &lt;BR /&gt;
"8750999,""*ALL"",JPD910,""11484/6788"",UNKNOWN,""Mon Sep 15 10:52:20.411000"",""IPCMISC.C299"&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;

&lt;P&gt;9/13/14 &lt;BR /&gt;
3:28:27.380 PM&lt;BR /&gt;&lt;BR /&gt;
"   State information for process 7764, User=6635103, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP07, Version=LIS0001, Thread ID=12632, Thread Name=WRK:Starting jdeCallObject."""&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;

&lt;P&gt;9/13/14 &lt;BR /&gt;
3:28:27.380 PM&lt;BR /&gt;&lt;BR /&gt;
"6635103,""*ALL"",JPD910,""2664/14920"",UNKNOWN,""Sat Sep 13 15:28:27.380002"",""IPCMISC.C299"&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;

&lt;P&gt;9/11/14 &lt;BR /&gt;
12:59:54.203 PM &lt;BR /&gt;
"   State information for process 10784, User=6107085, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP04, Version=LIS0001, Thread ID=13536, Thread Name=WRK:Starting jdeCallObject."""&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;

&lt;P&gt;9/11/14 &lt;BR /&gt;
12:59:54.203 PM &lt;BR /&gt;
"6107085,""*ALL"",JPD910,""12760/14360"",UNKNOWN,""Thu Sep 11 12:59:54.203001"",""IPCMISC.C299"&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;In last, I make the same process with a index name test (index=test sourcetype=tes), but now, I has configured manually the sourcetype  before saving. This give me the results like follow:&lt;/P&gt;

&lt;P&gt;User,Role,Environment,PID,"Thread_Name","Date_Thread","File_Thread"&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = tes&lt;/P&gt;

&lt;P&gt;9/15/14 &lt;BR /&gt;
10:52:20.411 AM &lt;BR /&gt;
8750321,"*ALL",JPD910,"11484/6788",UNKNOWN,"Mon Sep 15 10:52:20.411000","IPCMISC.C299&lt;BR /&gt;
    State information for process 10036, User=8750321, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP06, Version=LIS0001, Thread ID=9280, Thread Name=WRK:8750321_09D55650_P5542319."&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = tes&lt;/P&gt;

&lt;P&gt;9/13/14 &lt;BR /&gt;
3:28:27.380 PM&lt;BR /&gt;&lt;BR /&gt;
6635103,"*ALL",JPD910,"2664/14920",UNKNOWN,"Sat Sep 13 15:28:27.380002","IPCMISC.C299&lt;BR /&gt;
    State information for process 7764, User=6635103, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP07, Version=LIS0001, Thread ID=12632, Thread Name=WRK:Starting jdeCallObject."&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = tes&lt;/P&gt;

&lt;P&gt;9/11/14 &lt;BR /&gt;
12:59:54.203 PM &lt;BR /&gt;
6107085,"*ALL",JPD910,"12760/14360",UNKNOWN,"Thu Sep 11 12:59:54.203001","IPCMISC.C299&lt;BR /&gt;
    State information for process 10784, User=6107085, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP04, Version=LIS0001, Thread ID=13536, Thread Name=WRK:Starting jdeCallObject."&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = tes&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;This is the same result with first step only that, first event represent the head line of csv file.&lt;BR /&gt;
In conclusion, I can say that, the search results adds up when source is modified because the sourcetype is not configured manually.&lt;/P&gt;

&lt;P&gt;Note: If you don't specify a sourcetype when you searching, the events is adds(duplication) anytime you re-launch a search (index=test)  like this:  example, when i launch a same search of step3 without it sourcetype  after one day, i obtain now 10 events  like follow:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;12/10/14 
1:47:56.000 PM  
User,Role,Environment,PID,"Thread_Name","Date_Thread","File_Thread"
host = student16-PC source = APPCB02.csv sourcetype = tes


9/15/14 
10:52:20.411 AM 
"   State information for process 10036, User=8750321, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP06, Version=LIS0001, Thread ID=9280, Thread Name=WRK:8750321_09D55650_P5542319."""
host = student16-PC source = C:\Users\student16\Desktop\APPCB022.csv sourcetype = csv


9/15/14 
10:52:20.411 AM 
"8758888,""*ALL"",JPD910,""11484/6788"",UNKNOWN,""Mon Sep 15 10:52:20.411000"",""IPCMISC.C299"
host = student16-PC source = C:\Users\student16\Desktop\APPCB022.csv sourcetype = csv


9/15/14 
10:52:20.411 AM 
8750321,"*ALL",JPD910,"11484/6788",UNKNOWN,"Mon Sep 15 10:52:20.411000","IPCMISC.C299
    State information for process 10036, User=8750321, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP06, Version=LIS0001, Thread ID=9280, Thread Name=WRK:8750321_09D55650_P5542319."
host = student16-PC source = APPCB02.csv sourcetype = tes


9/13/14 
3:28:27.380 PM  
"   State information for process 7764, User=6635103, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP07, Version=LIS0001, Thread ID=12632, Thread Name=WRK:Starting jdeCallObject."""
host = student16-PC source = C:\Users\student16\Desktop\APPCB022.csv sourcetype = csv


9/13/14 
3:28:27.380 PM  
"6635103,""*ALL"",JPD910,""2664/14920"",UNKNOWN,""Sat Sep 13 15:28:27.380002"",""IPCMISC.C299"
host = student16-PC source = C:\Users\student16\Desktop\APPCB022.csv sourcetype = csv


9/13/14 
3:28:27.380 PM  
6635103,"*ALL",JPD910,"2664/14920",UNKNOWN,"Sat Sep 13 15:28:27.380002","IPCMISC.C299
    State information for process 7764, User=6635103, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP07, Version=LIS0001, Thread ID=12632, Thread Name=WRK:Starting jdeCallObject."
host = student16-PC source = APPCB02.csv sourcetype = tes


9/11/14 
12:59:54.203 PM 
"   State information for process 10784, User=6107085, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP04, Version=LIS0001, Thread ID=13536, Thread Name=WRK:Starting jdeCallObject."""
host = student16-PC source = C:\Users\student16\Desktop\APPCB022.csv sourcetype = csv


9/11/14 
12:59:54.203 PM 
"6107085,""*ALL"",JPD910,""12760/14360"",UNKNOWN,""Thu Sep 11 12:59:54.203001"",""IPCMISC.C299"
host = student16-PC source = C:\Users\student16\Desktop\APPCB022.csv sourcetype = csv


9/11/14 
12:59:54.203 PM 
6107085,"*ALL",JPD910,"12760/14360",UNKNOWN,"Thu Sep 11 12:59:54.203001","IPCMISC.C299
    State information for process 10784, User=6107085, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP04, Version=LIS0001, Thread ID=13536, Thread Name=WRK:Starting jdeCallObject."
host = student16-PC source = APPCB02.csv sourcetype = tes
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Mon, 28 Sep 2020 18:26:20 GMT</pubDate>
    <dc:creator>ngatchasandra</dc:creator>
    <dc:date>2020-09-28T18:26:20Z</dc:date>
    <item>
      <title>Why search results adds up when source is modified?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145810#M40671</link>
      <description>&lt;P&gt;Hello friends,&lt;/P&gt;

&lt;P&gt;I have indexed my own .log file in to Splunk and there are about 10 events in that log files. I wonder why the number of events returned gets doubled if I make a change on the .log file manually (edit it on notepad and save). For example if i change the value of one field from A to B (field seperated by &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt; and let say there are x results, splunk will show x + x events for the new search. &lt;BR /&gt;
somebody please explain me how splunk works in this scenario?. Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Dec 2014 09:36:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145810#M40671</guid>
      <dc:creator>boney_s</dc:creator>
      <dc:date>2014-12-05T09:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why search results adds up when source is modified?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145811#M40672</link>
      <description>&lt;P&gt;did you add a &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;crcSalt = &amp;lt;SOURCE&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;in &lt;CODE&gt;inputs.conf&lt;/CODE&gt; for this log?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Dec 2014 09:46:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145811#M40672</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-12-05T09:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why search results adds up when source is modified?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145812#M40673</link>
      <description>&lt;P&gt;No. I tried including that command to input.conf but still not working.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Dec 2014 10:38:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145812#M40673</guid>
      <dc:creator>boney_s</dc:creator>
      <dc:date>2014-12-05T10:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why search results adds up when source is modified?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145813#M40674</link>
      <description>&lt;P&gt;don't do this, because this can cause exactly this - re-indexing files. Only include this if really needed.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Dec 2014 10:41:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145813#M40674</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-12-05T10:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why search results adds up when source is modified?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145814#M40675</link>
      <description>&lt;P&gt;When Splunk is monitoring a file or files in a folder, it creates a crc (Cyclic Redundancy Check) handler for each file, so as it will not re-index a file with same data (even though the file gets renamed). The attribute which handles this crc handler is called &lt;STRONG&gt;initCrcLength&lt;/STRONG&gt; and is present in &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/inputsconf"&gt;inputs.conf&lt;/A&gt;. &lt;/P&gt;

&lt;P&gt;Default value for this property is 256 bytes (first 256 bytes in the file). So, if you change anything in the file which is within the limit set by &lt;STRONG&gt;initCrcLength&lt;/STRONG&gt; attribute, Splunk will treat it as new file and will re-index all the entries (not just the updated entries).&lt;/P&gt;</description>
      <pubDate>Fri, 05 Dec 2014 20:39:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145814#M40675</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-12-05T20:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why search results adds up when source is modified?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145815#M40676</link>
      <description>&lt;P&gt;Thank you guys. So i need to reduce the initCrcLength. BTW what is the minimum value for that parameter?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Dec 2014 05:50:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145815#M40676</guid>
      <dc:creator>boney_s</dc:creator>
      <dc:date>2014-12-08T05:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why search results adds up when source is modified?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145816#M40677</link>
      <description>&lt;P&gt;Per documentations, it should be in the range of 256-1048576 so the minimum value is the default value. Is it possible for you to change the way you update the file, means if you just want to update one entry, create a file with just that entry or something?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Dec 2014 17:08:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145816#M40677</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-12-08T17:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why search results adds up when source is modified?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145817#M40678</link>
      <description>&lt;P&gt;Thanks my friend.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2014 03:59:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145817#M40678</guid>
      <dc:creator>boney_s</dc:creator>
      <dc:date>2014-12-09T03:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why search results adds up when source is modified?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145818#M40679</link>
      <description>&lt;P&gt;To answer this question, I have done the steps like follow:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;First time, i created a index and i indexed  a csv file with that index.  When I start search  by putting “index=test1” in search bar, the result give me 3 events:&lt;/P&gt;

&lt;P&gt;9/15/14 &lt;BR /&gt;
10:52:20.411 AM &lt;BR /&gt;
8750321,"*ALL",JPD910,"11484/6788",UNKNOWN,"Mon Sep 15 10:52:20.411000","IPCMISC.C299&lt;BR /&gt;
    State information for process 10036, User=8750321, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP06, Version=LIS0001, Thread ID=9280, Thread Name=WRK:8750321_09D55650_P5542319."&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;

&lt;P&gt;9/13/14 &lt;BR /&gt;
3:28:27.380 PM&lt;BR /&gt;&lt;BR /&gt;
6635103,"*ALL",JPD910,"2664/14920",UNKNOWN,"Sat Sep 13 15:28:27.380002","IPCMISC.C299&lt;BR /&gt;
    State information for process 7764, User=6635103, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP07, Version=LIS0001, Thread ID=12632, Thread Name=WRK:Starting jdeCallObject."&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;

&lt;P&gt;9/11/14 &lt;BR /&gt;
12:59:54.203 PM &lt;BR /&gt;
6107085,"*ALL",JPD910,"12760/14360",UNKNOWN,"Thu Sep 11 12:59:54.203001","IPCMISC.C299&lt;BR /&gt;
    State information for process 10784, User=6107085, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP04, Version=LIS0001, Thread ID=13536, Thread Name=WRK:Starting jdeCallObject."&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Second time, in by editing this csv file, I make a change of first value of first event like this:&lt;BR /&gt;
8750321 its become 8750999. &lt;BR /&gt;
When I re-indexed the same file with another index which I created and name it test2, the same search give me results like follow with 6 events:&lt;/P&gt;

&lt;P&gt;9/15/14 &lt;BR /&gt;
10:52:20.411 AM &lt;BR /&gt;
"   State information for process 10036, User=8750321, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP06, Version=LIS0001, Thread ID=9280, Thread Name=WRK:8750321_09D55650_P5542319."""&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;

&lt;P&gt;9/15/14 &lt;BR /&gt;
10:52:20.411 AM &lt;BR /&gt;
"8750999,""*ALL"",JPD910,""11484/6788"",UNKNOWN,""Mon Sep 15 10:52:20.411000"",""IPCMISC.C299"&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;

&lt;P&gt;9/13/14 &lt;BR /&gt;
3:28:27.380 PM&lt;BR /&gt;&lt;BR /&gt;
"   State information for process 7764, User=6635103, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP07, Version=LIS0001, Thread ID=12632, Thread Name=WRK:Starting jdeCallObject."""&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;

&lt;P&gt;9/13/14 &lt;BR /&gt;
3:28:27.380 PM&lt;BR /&gt;&lt;BR /&gt;
"6635103,""*ALL"",JPD910,""2664/14920"",UNKNOWN,""Sat Sep 13 15:28:27.380002"",""IPCMISC.C299"&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;

&lt;P&gt;9/11/14 &lt;BR /&gt;
12:59:54.203 PM &lt;BR /&gt;
"   State information for process 10784, User=6107085, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP04, Version=LIS0001, Thread ID=13536, Thread Name=WRK:Starting jdeCallObject."""&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;

&lt;P&gt;9/11/14 &lt;BR /&gt;
12:59:54.203 PM &lt;BR /&gt;
"6107085,""*ALL"",JPD910,""12760/14360"",UNKNOWN,""Thu Sep 11 12:59:54.203001"",""IPCMISC.C299"&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = csv&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;In last, I make the same process with a index name test (index=test sourcetype=tes), but now, I has configured manually the sourcetype  before saving. This give me the results like follow:&lt;/P&gt;

&lt;P&gt;User,Role,Environment,PID,"Thread_Name","Date_Thread","File_Thread"&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = tes&lt;/P&gt;

&lt;P&gt;9/15/14 &lt;BR /&gt;
10:52:20.411 AM &lt;BR /&gt;
8750321,"*ALL",JPD910,"11484/6788",UNKNOWN,"Mon Sep 15 10:52:20.411000","IPCMISC.C299&lt;BR /&gt;
    State information for process 10036, User=8750321, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP06, Version=LIS0001, Thread ID=9280, Thread Name=WRK:8750321_09D55650_P5542319."&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = tes&lt;/P&gt;

&lt;P&gt;9/13/14 &lt;BR /&gt;
3:28:27.380 PM&lt;BR /&gt;&lt;BR /&gt;
6635103,"*ALL",JPD910,"2664/14920",UNKNOWN,"Sat Sep 13 15:28:27.380002","IPCMISC.C299&lt;BR /&gt;
    State information for process 7764, User=6635103, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP07, Version=LIS0001, Thread ID=12632, Thread Name=WRK:Starting jdeCallObject."&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = tes&lt;/P&gt;

&lt;P&gt;9/11/14 &lt;BR /&gt;
12:59:54.203 PM &lt;BR /&gt;
6107085,"*ALL",JPD910,"12760/14360",UNKNOWN,"Thu Sep 11 12:59:54.203001","IPCMISC.C299&lt;BR /&gt;
    State information for process 10784, User=6107085, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP04, Version=LIS0001, Thread ID=13536, Thread Name=WRK:Starting jdeCallObject."&lt;BR /&gt;
host = student16-PC source = APPCB02.csv sourcetype = tes&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;This is the same result with first step only that, first event represent the head line of csv file.&lt;BR /&gt;
In conclusion, I can say that, the search results adds up when source is modified because the sourcetype is not configured manually.&lt;/P&gt;

&lt;P&gt;Note: If you don't specify a sourcetype when you searching, the events is adds(duplication) anytime you re-launch a search (index=test)  like this:  example, when i launch a same search of step3 without it sourcetype  after one day, i obtain now 10 events  like follow:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;12/10/14 
1:47:56.000 PM  
User,Role,Environment,PID,"Thread_Name","Date_Thread","File_Thread"
host = student16-PC source = APPCB02.csv sourcetype = tes


9/15/14 
10:52:20.411 AM 
"   State information for process 10036, User=8750321, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP06, Version=LIS0001, Thread ID=9280, Thread Name=WRK:8750321_09D55650_P5542319."""
host = student16-PC source = C:\Users\student16\Desktop\APPCB022.csv sourcetype = csv


9/15/14 
10:52:20.411 AM 
"8758888,""*ALL"",JPD910,""11484/6788"",UNKNOWN,""Mon Sep 15 10:52:20.411000"",""IPCMISC.C299"
host = student16-PC source = C:\Users\student16\Desktop\APPCB022.csv sourcetype = csv


9/15/14 
10:52:20.411 AM 
8750321,"*ALL",JPD910,"11484/6788",UNKNOWN,"Mon Sep 15 10:52:20.411000","IPCMISC.C299
    State information for process 10036, User=8750321, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP06, Version=LIS0001, Thread ID=9280, Thread Name=WRK:8750321_09D55650_P5542319."
host = student16-PC source = APPCB02.csv sourcetype = tes


9/13/14 
3:28:27.380 PM  
"   State information for process 7764, User=6635103, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP07, Version=LIS0001, Thread ID=12632, Thread Name=WRK:Starting jdeCallObject."""
host = student16-PC source = C:\Users\student16\Desktop\APPCB022.csv sourcetype = csv


9/13/14 
3:28:27.380 PM  
"6635103,""*ALL"",JPD910,""2664/14920"",UNKNOWN,""Sat Sep 13 15:28:27.380002"",""IPCMISC.C299"
host = student16-PC source = C:\Users\student16\Desktop\APPCB022.csv sourcetype = csv


9/13/14 
3:28:27.380 PM  
6635103,"*ALL",JPD910,"2664/14920",UNKNOWN,"Sat Sep 13 15:28:27.380002","IPCMISC.C299
    State information for process 7764, User=6635103, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP07, Version=LIS0001, Thread ID=12632, Thread Name=WRK:Starting jdeCallObject."
host = student16-PC source = APPCB02.csv sourcetype = tes


9/11/14 
12:59:54.203 PM 
"   State information for process 10784, User=6107085, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP04, Version=LIS0001, Thread ID=13536, Thread Name=WRK:Starting jdeCallObject."""
host = student16-PC source = C:\Users\student16\Desktop\APPCB022.csv sourcetype = csv


9/11/14 
12:59:54.203 PM 
"6107085,""*ALL"",JPD910,""12760/14360"",UNKNOWN,""Thu Sep 11 12:59:54.203001"",""IPCMISC.C299"
host = student16-PC source = C:\Users\student16\Desktop\APPCB022.csv sourcetype = csv


9/11/14 
12:59:54.203 PM 
6107085,"*ALL",JPD910,"12760/14360",UNKNOWN,"Thu Sep 11 12:59:54.203001","IPCMISC.C299
    State information for process 10784, User=6107085, Role=*ALL, Environment=JPD910, Profile=NONE, Application=P5542319, Client Machine=WKCLSE1WEBCP04, Version=LIS0001, Thread ID=13536, Thread Name=WRK:Starting jdeCallObject."
host = student16-PC source = APPCB02.csv sourcetype = tes
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:26:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145818#M40679</guid>
      <dc:creator>ngatchasandra</dc:creator>
      <dc:date>2020-09-28T18:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why search results adds up when source is modified?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145819#M40680</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;

&lt;P&gt;I have one more question related to the one above .I have indexed one DB table in splunk and its data changes frequently.  Why splunk shows previously stored results even if the DB table is empty. Is there any way to show real time DB table values in Splunk?. I.e if table has 10 rows splunk should show "10 events" and if table has 0 rows splunk should show "0 events". Is that possible?&lt;/P&gt;

&lt;P&gt;Thanks in advance &lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2014 12:07:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145819#M40680</guid>
      <dc:creator>boney_s</dc:creator>
      <dc:date>2014-12-15T12:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why search results adds up when source is modified?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145820#M40681</link>
      <description>&lt;P&gt;read the docs about DB connect &lt;A href="http://docs.splunk.com/Documentation/DBX/latest/DeployDBX/Installtheconnector"&gt;http://docs.splunk.com/Documentation/DBX/latest/DeployDBX/Installtheconnector&lt;/A&gt; and the &lt;CODE&gt;dbquery&lt;/CODE&gt; command &lt;A href="http://docs.splunk.com/Documentation/DBX/1.1.6/DeployDBX/Commands"&gt;http://docs.splunk.com/Documentation/DBX/1.1.6/DeployDBX/Commands&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2014 12:35:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145820#M40681</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-12-15T12:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: Why search results adds up when source is modified?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145821#M40682</link>
      <description>&lt;P&gt;Thanks man that really saved my time.&lt;BR /&gt;
         BTW what is the minimum time I can give for a "scheduled report". Right now I am using  &lt;CODE&gt;*/1 * * * *&lt;/CODE&gt; (cron) for running it every 1 minute I guess. Is it possible to reduce this time to seconds range.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2014 04:58:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-search-results-adds-up-when-source-is-modified/m-p/145821#M40682</guid>
      <dc:creator>boney_s</dc:creator>
      <dc:date>2014-12-16T04:58:50Z</dc:date>
    </item>
  </channel>
</rss>

