Splunk Enterprise Security

Different results for same search on same search head for rest call or save search.

sohailmohammed
Explorer

Hello there,

 I get different results when I run a rest call. 
For example I ran a rest command to bring all the dashboards on h1 search head it brings 300 to me and for my colleague it brings 305 on same h1 search head. What may be the problem ?

Also if I get 300 results on SH H1, I see different count on H2 with 310 results.. what is the issue here for this inconsistencies ? 

Labels (1)
Tags (1)
0 Karma

diogofgm
SplunkTrust
SplunkTrust

It could be different permissions between the users.


------------
Hope I was able to help you. If so, some karma would be appreciated.
0 Karma

sohailmohammed
Explorer

Same search , same time range, same search head and same role. 

0 Karma

securitypaul
Explorer

Please post the rest call and a screenshot of the different results.

0 Karma

sohailmohammed
Explorer

| rest splunk_server=local /servicesNS/-/-/data/ui/views | stats count by label, title, eai:appName, author

results for user1: 580

results for user2: 600

 

same search same role same time and same search head.

0 Karma

securitypaul
Explorer

Could well be a permissions issue. If I run the search as admin I get 301 results, as a Splunk user I get 282 results.

Do both users have the same permissions?

0 Karma

sohailmohammed
Explorer

same search,  same role, same permission, same time and same search head.

Thank you

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...