Why is there a difference between the number of events scanned in both these queries?
Using below query getting statistics count 25 and number of events (Events label below search query) as 214.
| tstats values(XXXX.product_name) as "Product Name" from datamodel=XXXX where (XXXX.threat_name="*") by XXXX.threat_name
But, Using
| tstats values(XXXX.product_name) as "Product Name" from datamodel=XXXX where (XXXX.threat_name!="") by XXXX.threat_name
getting statistics count same 25 and number of events (Events label below search query) as 5,468.
1) Are you running for a fixed time frame, such as earliest=-1d@d latest=@d
?
2) Compare the output. Which threat_name are the events missing from?
Thanks for your response DalJeanis.
Yes, I am running queries for a fixed time frame.
I have updated the question as per my research. please see the updated question.
A few things to check here:
summareisonly
in the tstats
search, are the DMA searches running and summaries are available?get-_index
searchJust a starting point, but good to check ...
cheers, MuS
Thanks for the answer MuS.
I have updated the question as per my research and found the problem in this scenario.