Splunk Enterprise Security

Different results for same search on same search head for rest call or save search.

sohailmohammed
Explorer

Hello there,

 I get different results when I run a rest call. 
For example I ran a rest command to bring all the dashboards on h1 search head it brings 300 to me and for my colleague it brings 305 on same h1 search head. What may be the problem ?

Also if I get 300 results on SH H1, I see different count on H2 with 310 results.. what is the issue here for this inconsistencies ? 

Labels (1)
Tags (1)
0 Karma

diogofgm
SplunkTrust
SplunkTrust

It could be different permissions between the users.


------------
Hope I was able to help you. If so, some karma would be appreciated.
0 Karma

sohailmohammed
Explorer

Same search , same time range, same search head and same role. 

0 Karma

securitypaul
Explorer

Please post the rest call and a screenshot of the different results.

0 Karma

sohailmohammed
Explorer

| rest splunk_server=local /servicesNS/-/-/data/ui/views | stats count by label, title, eai:appName, author

results for user1: 580

results for user2: 600

 

same search same role same time and same search head.

0 Karma

securitypaul
Explorer

Could well be a permissions issue. If I run the search as admin I get 301 results, as a Splunk user I get 282 results.

Do both users have the same permissions?

0 Karma

sohailmohammed
Explorer

same search,  same role, same permission, same time and same search head.

Thank you

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...