Splunk Enterprise

splunk dashboard studio result variance

selvam_sekar
Path Finder

Hi,

I am calculating the difference between two search results  as below. And, sometime the panel takes bit time to return the results, thus the variance is showing false count.

Please could you suggest ? how to fix

Thanks in advance.

SPL:

| makeresults
| eval variance=$MA:result.macoscount$ - $COSMOS:result.cosmacount$
| table variance

Issue:

selvam_sekar_0-1714031903333.png

middle panel (with blue color) result is "MA to COSMOS value "- COSMOS to P.H.B"

 

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Are the time ranges for both searches the same - if the search is to "now" as latest time, then naturally they could come up with different results depending on when the search is dispatched and how long it takes to run.

I am guessing these are some kind of requests, so MA->COSMOS->PHB - is a negative figure not possible? Presumably there can be requests from COSMOS->PHB at the start of the search window that do not have corresponding requests inside the range from MA->COSMOS - without knowing your environment it's impossible to know.

0 Karma

Richfez
SplunkTrust
SplunkTrust

I get the feeling you've somehow overflowed one or both of your counts?

Why not split it out temporarily into three pieces - one being "$MA:result.macoscount$", another being "$COSMOS:result.cosmacount$" then finally the subtraction.  If nothing else it'll help narrow down what's going on!

 

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...