splunk search produces different results when the same query is run several times - why?

New Member

I run the query
index=* tag=xyz customertype=abc action=failure sourcetype=abc123_winlog | dedup _time, user, src, dest
in fast mode, for the last 7 days

how can I get different results???
on day 4 for example I get 15000 events shown for one period of time (midnight to 1am), and the same time period in a second run of the query then returns 6000 events, how can this be?
splunk version 6.6.1

Path Finder

Seems like the dedup is playing games. What happens if you dedup the _raw field ? do you still get different results?

