Splunk Enterprise

splunk dashboard studio result variance

selvam_sekar
Path Finder

Hi,

I am calculating the difference between two search results  as below. And, sometime the panel takes bit time to return the results, thus the variance is showing false count.

Please could you suggest ? how to fix

Thanks in advance.

SPL:

| makeresults
| eval variance=$MA:result.macoscount$ - $COSMOS:result.cosmacount$
| table variance

Issue:

selvam_sekar_0-1714031903333.png

middle panel (with blue color) result is "MA to COSMOS value "- COSMOS to P.H.B"

 

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Are the time ranges for both searches the same - if the search is to "now" as latest time, then naturally they could come up with different results depending on when the search is dispatched and how long it takes to run.

I am guessing these are some kind of requests, so MA->COSMOS->PHB - is a negative figure not possible? Presumably there can be requests from COSMOS->PHB at the start of the search window that do not have corresponding requests inside the range from MA->COSMOS - without knowing your environment it's impossible to know.

0 Karma

Richfez
SplunkTrust
SplunkTrust

I get the feeling you've somehow overflowed one or both of your counts?

Why not split it out temporarily into three pieces - one being "$MA:result.macoscount$", another being "$COSMOS:result.cosmacount$" then finally the subtraction.  If nothing else it'll help narrow down what's going on!

 

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...