If I search | eventcount summarize=false index=index3 the answer is count : 32339388
If I search index=index3 182154 event events are count with empty days 42 days before the last days.
I've made 2 changes before to have this behavior :
of course i'm on "all-time" period (or hope to be, because it's look like I'm not)
thank's for your help 🙂
OK I've found the limit : "Search auto-finalized after disk usage limit (0MB) reached. "
OK I've found the limit : "Search auto-finalized after disk usage limit (0MB) reached. "
Did you run both the query for all time?
Thank's. Yes. I did it with the web interface. Is there a SPL command to include all time period ?
You could use earliest=-100y latest=now
https://docs.splunk.com/Documentation/Splunk/7.1.0/SearchReference/SearchTimeModifiers