Dashboards & Visualizations

Records count in dashboard charts is not matching with the records count in dashboard table where same query is used

pasokkum
Path Finder

Hi Team,

We have created a custom dashboard in Splunk. Records count in dashboard charts is not matching with the records count in dashboard table where same query is used.It is showing less number of records for all time and more records for a particular time range.

Please let us know how we can resolve this issue

Thanks,
Soumya

Tags (1)
0 Karma

mcronkrite
Splunk Employee
Splunk Employee

Which App Search Context are you using.
For example if you are in the Green Search and Reporting an do a search vs being in the Blue Palo Alto App.
Apps have different permissions on fields. So your query might be referencing a fields from Palo Alto that does not have global scope.

Also are you in Fast, Smart or Verbose mode?
Fast mode means only the | stats fields are brought back.
Smart mode means the fields that you have explicitly downloaded apps for apply, when in the right app context.
And Verbose means no fields are explicitly setup and Splunk is learning the key values on the fly.

Are you running as the same user in both cases?

0 Karma

woodcock
Esteemed Legend

Post the search AND both URLs (everything after .../app/). Then I will be able to answer your question.

0 Karma

somesoni2
Revered Legend

Could you provide the query that you're using ? I've seen Splunk dropping events, with no error if the query is very complex/expensive, due to high memory usage by search.

0 Karma

pradeepkumarg
Influencer

Does the chart panel have any warning or error message about truncating the data because of hitting some limits? Try running the search independently to find any clue in the job inspector.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...