Knowledge Management

Pivot does not appear to return all expected fields from the report

bfreese
Engager

Looking at a report generated by a pivot on a data model, in the report we get about 2.3 million events back every time we run the report. The report is not on live data, so no more data is being added to the data model. When we then view this report as a pivot, we seem to get a fraction of the events back, even though it is running the same search string as the report. Instead of 2.3 million events, we get something like 40k, and it is a different number every time. We have max rows set to 0 and columns set to 300, which is way more than there could be.

From the report, we consistently get 638 rows back, but in a pivot view with max rows set to 0, we seem to get a random number of rows back, generally anywhere between 200 and 400. Never close to the 638 we would expect on the same search string.

The other odd behavior is the event count goes up every time I hit the refresh button. In short, the report generated from this pivot string is consistent, but the pivot view seems very inconsistent.

Is this expected behavior?

Thanks for your help.

bfreese

Labels (1)
0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...