We recently upgraded to splunk 6.6.3, and recently we noticed strange issue with one of our datamodel
We have datamodel "Datacenter" and below if the query I am running against that datamodel to pull ports and counts. Now when I run below query In fast or smart mode I get different result vs Verbose mode. Something has changed recently after we did upgrade.
I found a similar problem on searches two years ago when searching on many buckets (169) but not present when searching on few buckets (4).
So I opended a case to Splunk Support.
They answered that it was a bug solved in the 6.4.x version, and I verified that the problem isn't still present after upgrade..