Splunk Search

Different search results quetion

johefu
Loves-to-Learn

Hello all,

Running the following search (direct count) at different times of the day for the same time period I receive different results;

sourcetype=x index=y access_method="Explicit Proxy"
| table app,category,activity,user
| dedup user
| stats dc(user) by app

I can use this search but also get different results for the same time period, last 90 days;

sourcetype=x index=y access_method="Explicit Proxy"
| table app,category,activity,user
| dedup user
| stats count by app

Results look like this;

Appdc(user)
app 1499
app236
app319

 

Any suggestions on what maybe my issue?

Thanks

 

Labels (1)
0 Karma

johefu
Loves-to-Learn

I am using the date range, 2/1 

johefu_0-1621537503219.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What time periods are you using, earliest and latest?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...