Splunk Search

Different Results From Same Query

jack_sumatra
Explorer

I have question.

 

Can anyone explain why same search query given different results in different time range?

This is time range between 2021-02-24, hour 08:00:00 to 10:59:59

image_2021-02-24_133247.png

 

This is time range between 2021-02-24, hour 09:00:00 to 09:59:59

image_2021-02-24_133355.png

 

Why the result on hour 09:00:00 different, one show 81 and the other one 387.

 

Thank you

Labels (3)
0 Karma
1 Solution

gcusello
Esteemed Legend

Hi @jack_sumatra,

Have you the same events in both the time periods?

probably you have different events in the second one so you have a different result, it isn't a strange behaviour. 

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
Esteemed Legend

Hi @jack_sumatra,

Have you the same events in both the time periods?

probably you have different events in the second one so you have a different result, it isn't a strange behaviour. 

Ciao.

Giuseppe

0 Karma

gcusello
Esteemed Legend

Hi @jack_sumatra,

good for you, see next time!

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated 😉

Tags (1)
0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...