I am running my Splunk application on version 8.1.1. Several observations from the result when using different search modes to run on the same SPL.
I am having a tstats command to retrieve data from a specific index and further process with stats, lookup, eventstats, and streamstats commands. When the number of event is greater than 1M, the following issues are observed in different search mode,
The number of the sum(count) is different
The total number of rows in statistics tab is different
Some of the column values displayed in another column (e.g. value belongs to field_13 is shown under column field_2)