Splunk Search

Why do the REST API and Splunk GUI give different results for the same query?

btoomey
New Member

When I run the query search index=* sourcetype="XXX" earliest=-7d@d latest=-6d@d | stats count via the REST API, I get a count of 2752. (Note: I'm using the Python requests library to submit the query.) However, when I run the exact same query via the Splunk GUI, I get a count of 197395.

I realize that my problem is similar to the one explored in this question: https://answers.splunk.com/answers/25431/inconsistency-between-splunk-api-vs-gui-search-results.html.... However, I use the | stats count and results endpoint approach suggested by that answer. Also, even if the count was also being capped at 100000 events as happens with the eventCount property, the count is still far below 100000. Thus, my problem must have a different cause.

Thanks!

Tags (1)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...