Splunk Search

Missing seconds in Realtime query with 10ms span on python-sdk

timoti
Explorer

Hi, i'm trying to get Splunk realtime results using splunk's python-sdk.

Everything works well, but in the results, there is a missing second : I don't know whether there is a limitation or if I missed a parameter in the query? This is really embarrassing.

Here's my python code :

Capture d’écran 2020-11-25 à 10.49.12.pngCapture d’écran 2020-11-25 à 10.48.59.png

And here are the results:

As you can see, the entire second :  '2020-11-25T10:42:26' is missing, and will never appear in the results. Do you have any idea where this might come from?

Capture d’écran 2020-11-25 à 10.45.43.png

 

I even tried to "manually" create a timechart using ' search index=_internal bin _time span=10ms | chart count by _time'; and this this case, there is a missing millisecond (not second ).

There is a missing second every 5-10 results

I can't figure out why this is not working properly.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...