Thanks. In my case in certain "host" there is an analysis of a certain file which is loaded. That is contents of the file don't change. What in this case will help me? Doesn't help to clean a cache
Mh, using the host field not for the host, but for a grouping by day isn't very good practice. However, it should still work. Did you try this:
| tstats prestats=t count where host=01042018 by _time sourcetype
| timechart count by sourcetype
This should give you a timechart diagram of the data, and that shouldn't change on every query.
This is normal when your host is forwarding events into splunk continuously. Also, if you are searching for a time in the past (like yesterday), and it is still growing, it is possible that new events coming into splunk are either arriving very late, or the timestamp is being mis-interpreted and placed into the past.