<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: query in fast mode showing incorrect data and generate wrong result in chart in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/query-in-fast-mode-showing-incorrect-data-and-generate-wrong/m-p/191009#M54965</link>
    <description>&lt;P&gt;Yes it's unexpected, But if you think of your search as a series of steps, the next step can only operate what's given to it by the previous step. Therefore extractions for cLabel are only useful to timechart if they are extracted by the base search. Now part of how fast mode works is that it only attempts to extract fields as needed ( see the &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Search/Changethesearchmode"&gt;doc&lt;/A&gt; ). To successfully search for all events where &lt;CODE&gt;index=x sourcetype=y&lt;/CODE&gt; Splunk needs to do no extractions as index and sourcetype are default fields. However adding the condition that the cLabel field exists, Splunk now needs to do the extraction of cLabel in order to determine if a result meets this additional criteria. (Remember, Splunk is schemaless, and as a result most fields are extracted at search time only. While you know that the field is always filled in, that is something Splunk needs to see for itself)&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jan 2015 15:37:46 GMT</pubDate>
    <dc:creator>acharlieh</dc:creator>
    <dc:date>2015-01-23T15:37:46Z</dc:date>
    <item>
      <title>query in fast mode showing incorrect data and generate wrong result in chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/query-in-fast-mode-showing-incorrect-data-and-generate-wrong/m-p/191007#M54963</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have two fields in events, with which I am preparing line chart&lt;BR /&gt;
both the fields information&lt;BR /&gt;
 1. All the events have both these fields&lt;BR /&gt;
 2. Both the fields have some value in it (It's non-empty and Non NULL)&lt;BR /&gt;
     -- readIOps has numbers&lt;BR /&gt;
     -- cLabel has alphanumeric value (with which I have to group by - this column has 2 distinct values)&lt;/P&gt;

&lt;P&gt;Line chart query looks like&lt;BR /&gt;
index=indexName sourcetype=somessourcetype | timechart mean(readIOps) AS reads by cLabel&lt;/P&gt;

&lt;P&gt;Since this query is for chart it by default runs on fast mode and running this query on fast mode shows wrong data&lt;BR /&gt;
(In line chart, It shows one line with name "NULL" and result I notice was clubbing two distinct values of cLabel)&lt;/P&gt;

&lt;P&gt;When I open this query in search, it produce wrong table (with one NULL Column) and it was showing fast mode in search mode&lt;BR /&gt;
"changing fast mode to verbose mode shows correct result in the search" again reverting back to fast mode shows issue&lt;/P&gt;

&lt;P&gt;I did not find any way to force chart search on verbose mode&lt;BR /&gt;
so I made a fix by changing chart query as below, which produce correct result in chart as well as in fast mode searches&lt;BR /&gt;
index=indexName sourcetype=somessourcetype cLabel=* | timechart mean(readIOps) AS reads by cLabel&lt;/P&gt;

&lt;P&gt;See that cLabel is not null and not empty so ideally cLabel=* should not have any impact in event fetching&lt;/P&gt;

&lt;P&gt;My question is, Is this a splunk bug because &lt;BR /&gt;
fast mode, smart mode and verbose mode ideally should show same results for chart?&lt;/P&gt;

&lt;P&gt;Is there any guideline for this kind of issues or chart preparation to avoid such issues&lt;/P&gt;

&lt;P&gt;Thanks and Best Regards&lt;BR /&gt;
- Shreyans Soni&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2015 14:51:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/query-in-fast-mode-showing-incorrect-data-and-generate-wrong/m-p/191007#M54963</guid>
      <dc:creator>shreyans</dc:creator>
      <dc:date>2015-01-23T14:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: query in fast mode showing incorrect data and generate wrong result in chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/query-in-fast-mode-showing-incorrect-data-and-generate-wrong/m-p/191008#M54964</link>
      <description>&lt;P&gt;this looks like similar issue in advanced xml at &lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/177962/how-to-enable-verbose-mode-as-default-in-advanced.html"&gt;http://answers.splunk.com/answers/177962/how-to-enable-verbose-mode-as-default-in-advanced.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;but unanswered&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2015 14:57:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/query-in-fast-mode-showing-incorrect-data-and-generate-wrong/m-p/191008#M54964</guid>
      <dc:creator>shreyans</dc:creator>
      <dc:date>2015-01-23T14:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: query in fast mode showing incorrect data and generate wrong result in chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/query-in-fast-mode-showing-incorrect-data-and-generate-wrong/m-p/191009#M54965</link>
      <description>&lt;P&gt;Yes it's unexpected, But if you think of your search as a series of steps, the next step can only operate what's given to it by the previous step. Therefore extractions for cLabel are only useful to timechart if they are extracted by the base search. Now part of how fast mode works is that it only attempts to extract fields as needed ( see the &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Search/Changethesearchmode"&gt;doc&lt;/A&gt; ). To successfully search for all events where &lt;CODE&gt;index=x sourcetype=y&lt;/CODE&gt; Splunk needs to do no extractions as index and sourcetype are default fields. However adding the condition that the cLabel field exists, Splunk now needs to do the extraction of cLabel in order to determine if a result meets this additional criteria. (Remember, Splunk is schemaless, and as a result most fields are extracted at search time only. While you know that the field is always filled in, that is something Splunk needs to see for itself)&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2015 15:37:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/query-in-fast-mode-showing-incorrect-data-and-generate-wrong/m-p/191009#M54965</guid>
      <dc:creator>acharlieh</dc:creator>
      <dc:date>2015-01-23T15:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: query in fast mode showing incorrect data and generate wrong result in chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/query-in-fast-mode-showing-incorrect-data-and-generate-wrong/m-p/191010#M54966</link>
      <description>&lt;P&gt;Can you confirm that the two fields are in all cases non-null?    by running this search?   You kinda stated this already I know, but I'm just double checking.  Definitely sounds like a bug - I'm just trying to narrow it down. &lt;/P&gt;

&lt;P&gt;index=indexName sourcetype=somessourcetype | fillnull cLabel readIOps value="NO VALUE" | stats count by cLabel readIOps | search cLabel="NO VALUE" OR readIOps ="NO VALUE"&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jan 2015 20:16:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/query-in-fast-mode-showing-incorrect-data-and-generate-wrong/m-p/191010#M54966</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2015-01-26T20:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: query in fast mode showing incorrect data and generate wrong result in chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/query-in-fast-mode-showing-incorrect-data-and-generate-wrong/m-p/191011#M54967</link>
      <description>&lt;P&gt;However there's two problems here and this answer doesn't really address either.  a) If all the events have values for both fields, (and the field extractions are working as expected) then NULL should be impossible.        b) The search language optimization around extracting only the necessary fields,  (ie one part of what "fast mode" does) should absolutely see both the "mean(readIOps)" and also the "by cLabel", and it should just based on that know that extractions on those fields are required.   If you have the fields referenced in the search like that, there should be no need to additionally reference them in the search clause as a workaround.   &lt;/P&gt;</description>
      <pubDate>Mon, 26 Jan 2015 20:21:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/query-in-fast-mode-showing-incorrect-data-and-generate-wrong/m-p/191011#M54967</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2015-01-26T20:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: query in fast mode showing incorrect data and generate wrong result in chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/query-in-fast-mode-showing-incorrect-data-and-generate-wrong/m-p/191012#M54968</link>
      <description>&lt;P&gt;Hi, Thanks for looking into it&lt;/P&gt;

&lt;P&gt;I have executed above query &lt;BR /&gt;
index=indexName sourcetype=somessourcetype | fillnull cLabel readIOps value="NO VALUE" | stats count by cLabel readIOps | search cLabel="NO VALUE" OR readIOps ="NO VALUE"&lt;/P&gt;

&lt;P&gt;and verify that 145000 events have been filtered in Events tab and 0 in statistics tab.  This say no events with cLabel and readIOps with value "NO VALUE" and there by no null in actual events&lt;/P&gt;

&lt;P&gt;Let me know if you need any other info to debug it further&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jan 2015 05:42:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/query-in-fast-mode-showing-incorrect-data-and-generate-wrong/m-p/191012#M54968</guid>
      <dc:creator>shreyans</dc:creator>
      <dc:date>2015-01-27T05:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: query in fast mode showing incorrect data and generate wrong result in chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/query-in-fast-mode-showing-incorrect-data-and-generate-wrong/m-p/191013#M54969</link>
      <description>&lt;P&gt;Hi Acharlieh,&lt;/P&gt;

&lt;P&gt;thanks for your time and looking into this&lt;/P&gt;

&lt;P&gt;As you said "search as a series of steps" then see that my query is below&lt;BR /&gt;
index=indexName sourcetype=somessourcetype | timechart mean(readIOps) AS reads by cLabel&lt;/P&gt;

&lt;P&gt;that means I am extracting complete event with index=indexName and sourceType=somesourcetype and passing the same to timechart (I am not extracting few columns using table command and passing it to timechart) so Ideally timechart should get complete event and adding to that I am using readIOps and cLabel column in timechart thereby if timechart receives complete event then field extraction should happen at timechart level command on complete event.&lt;/P&gt;

&lt;P&gt;In a way you are right that if I explicitly extract field then search result is correct means below query worked fine&lt;BR /&gt;
index=indexName sourcetype=somessourcetype cLabel=* | timechart mean(readIOps) AS reads by cLabel&lt;/P&gt;

&lt;P&gt;but if you think of other splunk search commands then that is not how entire splunk search queries behavior is&lt;BR /&gt;
For example&lt;BR /&gt;
    index=indexName sourcetype=somessourcetype&lt;BR /&gt;
executing above command does not mean that after executing command you can only use index and sourcetype fields.  you still have choice of using other fields which meet above condition&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jan 2015 06:36:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/query-in-fast-mode-showing-incorrect-data-and-generate-wrong/m-p/191013#M54969</guid>
      <dc:creator>shreyans</dc:creator>
      <dc:date>2015-01-27T06:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: query in fast mode showing incorrect data and generate wrong result in chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/query-in-fast-mode-showing-incorrect-data-and-generate-wrong/m-p/191014#M54970</link>
      <description>&lt;P&gt;I probably am very beginner in splunk but as a splunk app developer, Ideally "Verbose mode and fast mode should produce same result" and if not by xyz reason then I am certainly looking for a way to pass search mode from my dashboard chart to explicitly search on verbose mode.&lt;BR /&gt;
adding to that we have at least two report of same issue already on answers.splunk.com and even that developer has fixed the issue like me (explicitly extracting field)&lt;/P&gt;

&lt;P&gt;If whatever I said make sense and worth investigating then can you guys please file a splunk bug here and let me know if I can continue with my query with cLabel=*  ? and when would the fix be available&lt;/P&gt;

&lt;P&gt;please correct me if I am making any mistake here.  You guys have better splunk understanding and insight than me &lt;/P&gt;

&lt;P&gt;Thanks and Best Regards&lt;BR /&gt;
- Shreyans Soni&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jan 2015 06:37:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/query-in-fast-mode-showing-incorrect-data-and-generate-wrong/m-p/191014#M54970</guid>
      <dc:creator>shreyans</dc:creator>
      <dc:date>2015-01-27T06:37:11Z</dc:date>
    </item>
  </channel>
</rss>

