Hello
I have a saved search that is running every month at 1st day. The search is not new and has been working a long time. The problem is that for the last run, it has returned count of 107 events instead of 108 for a specific date(2019-07-10). The search is running wiith timerange of Last month.
I start to analyze today and I wanted to check first what happens if I run the search now and after I did that I found out that the search returns now 108 events which is correct so what things could have gone wrong at 01.08 so that splunk has not returned 1 event?
We have checked index time of the events and are ok. We have checked that the indexers have not been down from a long time.
It is a cluster solution with 4 indexers + 1 new indexer which has been installed somewhere in july(can that have messed something?)
Splunks task is simply to return all data according to the search, so if Splunk has made error, can it be trusted?