Knowledge Management

outputlookup command doesnt send all the results of the query to the kvstore.

vn_g
Path Finder

Running the search query - returns 18 results in Statatics tab.
Running the search query with outputlookup command - returns 18 results in Statatics tab.
But when trying to query using inputlookup - returns 15 results in Statatics tab.

What could be the reason?

alt text

Labels (2)
0 Karma

DalJeanis
Legend

Shot in the dark. Check your query for duplicate results on anything that might be a key.

If that's not it, then please show the actual results, or a dummy version of what you see, so we can look further.

0 Karma

vn_g
Path Finder

Updated the screenshots for sample data. Their are other fields , which doesnt have the same value for every record.

inputlookup - RecordNo missing "5e940a21a0c53f0837420063"
outputlookup - xtime missing "2020-04-08T00:12:00.809"

0 Karma
Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...