We re-routed data from Splunk SaaS cloud to On-perm but we see event mismatch between these two instances, if I route the date to Splunk cloud all the sudden the event count increases but when I re-route the same data source to on-perm drastically the event count comes down for the same time period but don't see any error in the FW.
Fw-->Splunk SaaS more count.
Fw-->Splunk On-Perm less count.
Please find the screenshot and let me know what would be the issue and troubleshoot to fix this count mismatch. Thanks.
Hi @sathiyasun,
maybe there's a delay in data forwarding,
please run the same search using an old time period: e.g. yesterday or earliest=-4h@h latest=-3h@h.
Ciao.
Giuseppe