Splunk Enterprise

splunk dashboard studio result variance

selvam_sekar
Path Finder

Hi,

I am calculating the difference between two search results  as below. And, sometime the panel takes bit time to return the results, thus the variance is showing false count.

Please could you suggest ? how to fix

Thanks in advance.

SPL:

| makeresults
| eval variance=$MA:result.macoscount$ - $COSMOS:result.cosmacount$
| table variance

Issue:

selvam_sekar_0-1714031903333.png

middle panel (with blue color) result is "MA to COSMOS value "- COSMOS to P.H.B"

 

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Are the time ranges for both searches the same - if the search is to "now" as latest time, then naturally they could come up with different results depending on when the search is dispatched and how long it takes to run.

I am guessing these are some kind of requests, so MA->COSMOS->PHB - is a negative figure not possible? Presumably there can be requests from COSMOS->PHB at the start of the search window that do not have corresponding requests inside the range from MA->COSMOS - without knowing your environment it's impossible to know.

0 Karma

Richfez
SplunkTrust
SplunkTrust

I get the feeling you've somehow overflowed one or both of your counts?

Why not split it out temporarily into three pieces - one being "$MA:result.macoscount$", another being "$COSMOS:result.cosmacount$" then finally the subtraction.  If nothing else it'll help narrow down what's going on!

 

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...