Splunk Search

Conflicting Event count in Search App based upon time range

rahulgopal
Explorer

I executed this search on my data, over two different time ranges:

"malware" | timechart count

The time ranges were:

1) Last 4 hours

2) Last 60 minutes

The event count in the results, for a selected specific time stamp, were differently reported by the two searches above.

For instance, for the selected time of 10:45 am in the search results:

1) "Last 4 hours" reported the event count as 194

2) "Last 60 minutes" reported the event count as 32

Why this huge discrepancy ?

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

The discrepancy is caused by the differing bucket spans. Without specifying anything, a four-hour timechart will use buckets that span five minutes while a one-hour timechart will use buckets that span one minute.

If you add up the one-hour timechart's buckets for :45, :46, :47, :48, and :49 you will get 194.

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

The discrepancy is caused by the differing bucket spans. Without specifying anything, a four-hour timechart will use buckets that span five minutes while a one-hour timechart will use buckets that span one minute.

If you add up the one-hour timechart's buckets for :45, :46, :47, :48, and :49 you will get 194.

0 Karma

rahulgopal
Explorer

I found the issue on Splunk v5.0.3, and also on Splunk v6.

The screenshots from Splunk v6 can be accessed at:

1) Last 4 hours
https://www.dropbox.com/s/2ogseohypers9oy/count_4_hrs_Splunk6.jpg

2) Last 60 minutes
https://www.dropbox.com/s/9gjrlj3651iyz5d/count_60_mins_Splunk6.jpg

0 Karma

rahulgopal
Explorer

Upon further investigation, it appears it may be a bug in the Splunk search itself.

See my post about it at - "http://answers.splunk.com/answers/116526/conflicting-event-count-in-search-app-based-upon-time-range"

0 Karma

rahulgopal
Explorer
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...