When I count the results using either wc -l or by using grep to count the number of times the string containing my input file occurs in the file I get 18715731 results. I decided to try counting the string in case Splunk was including a new line in the output which would break wc counting. But any way that I use to count shows that there are 18715731 results.
In other words, I have exported 18,715,731 results but Splunk says there are only 18,531,517 events.
So there are 184,214 extra events in the output. The Splunk GUI has about 10% fewer events than the export tool gives.
How can I reliably pull data from Splunk? How do I know which of the Splunk reports are incorrect? The search results or the export results?