Knowledge Management

Pivot does not appear to return all expected fields from the report

bfreese
Engager

Looking at a report generated by a pivot on a data model, in the report we get about 2.3 million events back every time we run the report. The report is not on live data, so no more data is being added to the data model. When we then view this report as a pivot, we seem to get a fraction of the events back, even though it is running the same search string as the report. Instead of 2.3 million events, we get something like 40k, and it is a different number every time. We have max rows set to 0 and columns set to 300, which is way more than there could be.

From the report, we consistently get 638 rows back, but in a pivot view with max rows set to 0, we seem to get a random number of rows back, generally anywhere between 200 and 400. Never close to the 638 we would expect on the same search string.

The other odd behavior is the event count goes up every time I hit the refresh button. In short, the report generated from this pivot string is consistent, but the pivot view seems very inconsistent.

Is this expected behavior?

Thanks for your help.

bfreese

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...