After mv expand, events are split and when do search for a Splunk ID which is there in the event and try to display in statistics data is not the same in the search.
In the attachment the Splunk ID which is not the same as in the data
@sjothi1
Can you please share your search and sample events?