Splunk Search

Duplicate Results on Command-Line Query vice No Duplicates via UI

joemcmahon
Explorer

What would cause a command line query ( bin/splunk search "..." ) to return duplicate results over what the UI would return?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please explain what you mean by "duplicate" results, and what is your search, does this happen for just one search or all searches, does it happen for all timeframes or just certain ones?

0 Karma

joemcmahon
Explorer

Simple query, actually.

index=ourindex earliest=epoch1 latest=epoch2

Command line query returns 16 events, same query in UI returns 8 events. The 16 events have 8 duplicates.

Running 9.1.1 Splunk Enterprise. Search head cluster.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Do you get the same results when running the command line on all nodes in the cluster? How many nodes do you have?

0 Karma

joemcmahon
Explorer

We have a 4 search head (SH) cluster. 

I just found that, when running the command line query from each SH in the cluster,  it gives me the right number of events. 

When running that same command line query from a standalone SH, I get the duplicate results.  For example, from the Monitoring Console SH, the command line query gives me the duplicate results.

Same search peers in both cases.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...