Splunk Search

Conflicting Event count in Search App based upon time range

rahulgopal
Explorer

I executed this search on my data, over two different time ranges:

"malware" | timechart count

The time ranges were:

1) Last 4 hours

2) Last 60 minutes

The event count in the results, for a selected specific time stamp, were differently reported by the two searches above.

For instance, for the selected time of 10:45 am in the search results:

1) "Last 4 hours" reported the event count as 194

2) "Last 60 minutes" reported the event count as 32

Why this huge discrepancy ?

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

The discrepancy is caused by the differing bucket spans. Without specifying anything, a four-hour timechart will use buckets that span five minutes while a one-hour timechart will use buckets that span one minute.

If you add up the one-hour timechart's buckets for :45, :46, :47, :48, and :49 you will get 194.

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

The discrepancy is caused by the differing bucket spans. Without specifying anything, a four-hour timechart will use buckets that span five minutes while a one-hour timechart will use buckets that span one minute.

If you add up the one-hour timechart's buckets for :45, :46, :47, :48, and :49 you will get 194.

0 Karma

rahulgopal
Explorer

I found the issue on Splunk v5.0.3, and also on Splunk v6.

The screenshots from Splunk v6 can be accessed at:

1) Last 4 hours
https://www.dropbox.com/s/2ogseohypers9oy/count_4_hrs_Splunk6.jpg

2) Last 60 minutes
https://www.dropbox.com/s/9gjrlj3651iyz5d/count_60_mins_Splunk6.jpg

0 Karma

rahulgopal
Explorer

Upon further investigation, it appears it may be a bug in the Splunk search itself.

See my post about it at - "http://answers.splunk.com/answers/116526/conflicting-event-count-in-search-app-based-upon-time-range"

0 Karma

rahulgopal
Explorer
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...