Knowledge Management

Summary indexing inconsistent results across different apps

johandk
Path Finder

I am experiencing some very weird behaviour with SI's.

I have two apps. App1 and App2. App1 has a search named test_si and the other has the same search named test_si_1

The search string is exactly the same. The search is using some macros that are saved in App1 with global permissions.

The results I'm getting in the summary index vary wildly. The search in App1 gives the correct results. The search in App2 gives me results that are way too low.

Am I missing something obvious? Any ideas?

Tags (1)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Possibly field extractions are different between the apps? It's not just that the macros and the search string, but other search-time knowledge (fields, tags, eventtypes) might not be the same?

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

Possibly field extractions are different between the apps? It's not just that the macros and the search string, but other search-time knowledge (fields, tags, eventtypes) might not be the same?

johandk
Path Finder

It was in fact a very subtle bug with the regex. Gonna accept your answer for what its worth.

0 Karma

johandk
Path Finder

I am pretty sure now it is a extraction issue. But why when I run an interactive search all the extractions work perfectly... but with a saved search the results are different? Any ideas?

0 Karma

johandk
Path Finder

Most of the field extractions are done by another application, seperate from the 2 in question...

0 Karma

johandk
Path Finder

The App I'm running the saved searches from (and getting wrong results) is not visible in SplunkWeb. The App giving me correct results is visible in SplunkWeb. It's the only difference, but makes no sense still.

0 Karma