I am experiencing some very weird behaviour with SI's.
I have two apps. App1 and App2. App1 has a search named test_si and the other has the same search named test_si_1
The search string is exactly the same. The search is using some macros that are saved in App1 with global permissions.
The results I'm getting in the summary index vary wildly. The search in App1 gives the correct results. The search in App2 gives me results that are way too low.
Am I missing something obvious? Any ideas?
Possibly field extractions are different between the apps? It's not just that the macros and the search string, but other search-time knowledge (fields, tags, eventtypes) might not be the same?
Possibly field extractions are different between the apps? It's not just that the macros and the search string, but other search-time knowledge (fields, tags, eventtypes) might not be the same?
It was in fact a very subtle bug with the regex. Gonna accept your answer for what its worth.
I am pretty sure now it is a extraction issue. But why when I run an interactive search all the extractions work perfectly... but with a saved search the results are different? Any ideas?
Most of the field extractions are done by another application, seperate from the 2 in question...
The App I'm running the saved searches from (and getting wrong results) is not visible in SplunkWeb. The App giving me correct results is visible in SplunkWeb. It's the only difference, but makes no sense still.