Splunk Enterprise

What are other fields like "_serial", that may vary between searches in the same result?

gkeller
Explorer

Currently, we are using the Splunk Python SDK to get Splunk events based on a query and parse them.

We sometimes make multiple searches on overlapping time frames, and we  have a deduping mechanism based on hashing the entire JSON of the event.

However, this mechanism relies on the fact that the same event will return exactly the same in each search - which doesn't happen. For example, the "_serial" field might be different for the same event in consecutive searches.

My question is - are there any other fields like "_serial", that under some preconditions (any at all), might change their value between searches, without any actual change done to the event?

Thanks so much for the help!

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...