Splunk Dev

Splunk SDK search results smaller than GUI search

mohan94
New Member

Hi,

I am using the python SDK to make the following query

search sourcetype=WinEventLog:Security earliest=<epoch_time_1> latest=<epoch_time_2>

The difference between the two epoch times is 30 seconds. If I cut and past the query into Splunk GUI, I get slightly larger set of results. I use the same account for making the query in both cases. Depending on the source e.g., the more busier the source, I get a big difference. I see anywhere from a difference of 10 to 2000 results. What could I be doing wrong ?

-mohan

0 Karma

mohan94
New Member

Ok, responding to my own question. The problem happens only when epoch_time_2 was 'now' i.e you can't query something in the past to current time and get the exact results. epoc_time_2 should be less than now (i tried less by 30 seconds) and then the results were accurate. Hope it helps.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...