<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Conflicting Event count in Search App based upon time range in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Conflicting-Event-count-in-Search-App-based-upon-time-range/m-p/190584#M54887</link>
    <description>&lt;P&gt;The discrepancy is caused by the differing bucket spans. Without specifying anything, a four-hour timechart will use buckets that span five minutes while a one-hour timechart will use buckets that span one minute.&lt;/P&gt;

&lt;P&gt;If you add up the one-hour timechart's buckets for :45, :46, :47, :48, and :49 you will get 194.&lt;/P&gt;</description>
    <pubDate>Fri, 27 Dec 2013 08:55:08 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2013-12-27T08:55:08Z</dc:date>
    <item>
      <title>Conflicting Event count in Search App based upon time range</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Conflicting-Event-count-in-Search-App-based-upon-time-range/m-p/190580#M54883</link>
      <description>&lt;P&gt;I executed this search on my data, over two different time ranges:&lt;/P&gt;

&lt;P&gt;"malware" | timechart count &lt;/P&gt;

&lt;P&gt;The time ranges were:&lt;/P&gt;

&lt;P&gt;1) Last 4 hours&lt;/P&gt;

&lt;P&gt;2) Last 60 minutes&lt;/P&gt;

&lt;P&gt;The event count in the results, for a selected specific time stamp, were differently reported by the two searches above.&lt;/P&gt;

&lt;P&gt;For instance, for the selected time of 10:45 am in the search results:&lt;/P&gt;

&lt;P&gt;1) "Last 4 hours" reported the event count as 194&lt;/P&gt;

&lt;P&gt;2) "Last 60 minutes" reported the event count as 32&lt;/P&gt;

&lt;P&gt;Why this huge discrepancy ?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2013 16:51:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Conflicting-Event-count-in-Search-App-based-upon-time-range/m-p/190580#M54883</guid>
      <dc:creator>rahulgopal</dc:creator>
      <dc:date>2013-12-26T16:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Conflicting Event count in Search App based upon time range</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Conflicting-Event-count-in-Search-App-based-upon-time-range/m-p/190581#M54884</link>
      <description>&lt;P&gt;The screenshots can be accessed here:&lt;/P&gt;

&lt;P&gt;1) Last 4 hours&lt;BR /&gt;
&lt;A href="https://www.dropbox.com/s/nfncfxdrd5elqc7/count_4_hrs.jpg"&gt;https://www.dropbox.com/s/nfncfxdrd5elqc7/count_4_hrs.jpg&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;2) Last 60 minutes&lt;BR /&gt;
&lt;A href="https://www.dropbox.com/s/4qfm3kon3uem6g7/count_60_mins.jpg"&gt;https://www.dropbox.com/s/4qfm3kon3uem6g7/count_60_mins.jpg&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2013 16:55:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Conflicting-Event-count-in-Search-App-based-upon-time-range/m-p/190581#M54884</guid>
      <dc:creator>rahulgopal</dc:creator>
      <dc:date>2013-12-26T16:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: Conflicting Event count in Search App based upon time range</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Conflicting-Event-count-in-Search-App-based-upon-time-range/m-p/190582#M54885</link>
      <description>&lt;P&gt;Upon further investigation, it appears it may be a bug in the Splunk search itself.&lt;/P&gt;

&lt;P&gt;See my post about it at - "&lt;A href="http://answers.splunk.com/answers/116526/conflicting-event-count-in-search-app-based-upon-time-range"&gt;http://answers.splunk.com/answers/116526/conflicting-event-count-in-search-app-based-upon-time-range&lt;/A&gt;"&lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2013 16:58:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Conflicting-Event-count-in-Search-App-based-upon-time-range/m-p/190582#M54885</guid>
      <dc:creator>rahulgopal</dc:creator>
      <dc:date>2013-12-26T16:58:18Z</dc:date>
    </item>
    <item>
      <title>Re: Conflicting Event count in Search App based upon time range</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Conflicting-Event-count-in-Search-App-based-upon-time-range/m-p/190583#M54886</link>
      <description>&lt;P&gt;I found the issue on Splunk v5.0.3, and also on Splunk v6.&lt;/P&gt;

&lt;P&gt;The screenshots from Splunk v6 can be accessed at:&lt;/P&gt;

&lt;P&gt;1) Last 4 hours&lt;BR /&gt;
&lt;A href="https://www.dropbox.com/s/2ogseohypers9oy/count_4_hrs_Splunk6.jpg"&gt;https://www.dropbox.com/s/2ogseohypers9oy/count_4_hrs_Splunk6.jpg&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;2) Last 60 minutes&lt;BR /&gt;
&lt;A href="https://www.dropbox.com/s/9gjrlj3651iyz5d/count_60_mins_Splunk6.jpg"&gt;https://www.dropbox.com/s/9gjrlj3651iyz5d/count_60_mins_Splunk6.jpg&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2013 17:11:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Conflicting-Event-count-in-Search-App-based-upon-time-range/m-p/190583#M54886</guid>
      <dc:creator>rahulgopal</dc:creator>
      <dc:date>2013-12-26T17:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: Conflicting Event count in Search App based upon time range</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Conflicting-Event-count-in-Search-App-based-upon-time-range/m-p/190584#M54887</link>
      <description>&lt;P&gt;The discrepancy is caused by the differing bucket spans. Without specifying anything, a four-hour timechart will use buckets that span five minutes while a one-hour timechart will use buckets that span one minute.&lt;/P&gt;

&lt;P&gt;If you add up the one-hour timechart's buckets for :45, :46, :47, :48, and :49 you will get 194.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2013 08:55:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Conflicting-Event-count-in-Search-App-based-upon-time-range/m-p/190584#M54887</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-12-27T08:55:08Z</dc:date>
    </item>
  </channel>
</rss>

