Splunk Search

Timechart event result variations with time range picker

jamesboustead
Explorer

I am using the same timechart search query:

'search

| timechart span=1d sum(xxx)"

when I set the time range picker to yesterday preset (05/01/2021) I get a value of 20,000,000,000, however when I change the time range picker to week to date and view the stats table the value for 05/01/2021 is giving a completely different result (less than half the original value) - why is this?

 

Labels (1)
Tags (3)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @jamesboustead,

This is not expected behaviour.  Do you see any error on "Job" section after running search? Or can you share a screenshot of event count indicator just below search bar? What do you see as event count and time-range?

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

jamesboustead
Explorer

Hi @scelikok 

Getting no errors come up under the jobs section.

Please see screenshots of both event count indicators below:

image001.png

image002.png

It seems the second image for the week to date isn't picking up all the events it should, I'm not sure why,

 

Thanks

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...