When you write earliest=@d
, it executes search from midnight in Splunk Cloud. But in Splunk IT Service Intelligence (ITSI), it executes from the last 24 hours. My preference is for ITSI to perform as it does in Splunk Cloud. So is this an issue in Splunk?
Where are you defining that search? Is that in a KPI search? Also are you using a different version of ITSI than is installed on the cloud instance?
Hi ..
Thanks for your reply
Yes it's in the kpi base search ...
I use the same one that is installed on the cloud instance ....
Also when i put kpi summary as off then I get the same count as I get in base core splunk but when I change the kpi summary to on that's where I get the kpi count different ...
Are you sure the data is the same? Also, "earliest" and "latest" in a KPI Base Search is not recommended. We recommend that you use the KPI Interval option in the UI if you can.