Splunk Enterprise

splunk dashboard studio result variance

selvam_sekar
Path Finder

Hi,

I am calculating the difference between two search results  as below. And, sometime the panel takes bit time to return the results, thus the variance is showing false count.

Please could you suggest ? how to fix

Thanks in advance.

SPL:

| makeresults
| eval variance=$MA:result.macoscount$ - $COSMOS:result.cosmacount$
| table variance

Issue:

selvam_sekar_0-1714031903333.png

middle panel (with blue color) result is "MA to COSMOS value "- COSMOS to P.H.B"

 

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Are the time ranges for both searches the same - if the search is to "now" as latest time, then naturally they could come up with different results depending on when the search is dispatched and how long it takes to run.

I am guessing these are some kind of requests, so MA->COSMOS->PHB - is a negative figure not possible? Presumably there can be requests from COSMOS->PHB at the start of the search window that do not have corresponding requests inside the range from MA->COSMOS - without knowing your environment it's impossible to know.

0 Karma

Richfez
SplunkTrust
SplunkTrust

I get the feeling you've somehow overflowed one or both of your counts?

Why not split it out temporarily into three pieces - one being "$MA:result.macoscount$", another being "$COSMOS:result.cosmacount$" then finally the subtraction.  If nothing else it'll help narrow down what's going on!

 

 

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...