Splunk Dev

Splunk SDK search results smaller than GUI search

mohan94
New Member

Hi,

I am using the python SDK to make the following query

search sourcetype=WinEventLog:Security earliest=<epoch_time_1> latest=<epoch_time_2>

The difference between the two epoch times is 30 seconds. If I cut and past the query into Splunk GUI, I get slightly larger set of results. I use the same account for making the query in both cases. Depending on the source e.g., the more busier the source, I get a big difference. I see anywhere from a difference of 10 to 2000 results. What could I be doing wrong ?

-mohan

0 Karma

mohan94
New Member

Ok, responding to my own question. The problem happens only when epoch_time_2 was 'now' i.e you can't query something in the past to current time and get the exact results. epoc_time_2 should be less than now (i tried less by 30 seconds) and then the results were accurate. Hope it helps.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...