Splunk Search

Why do the REST API and Splunk GUI give different results for the same query?

btoomey
New Member

When I run the query search index=* sourcetype="XXX" earliest=-7d@d latest=-6d@d | stats count via the REST API, I get a count of 2752. (Note: I'm using the Python requests library to submit the query.) However, when I run the exact same query via the Splunk GUI, I get a count of 197395.

I realize that my problem is similar to the one explored in this question: https://answers.splunk.com/answers/25431/inconsistency-between-splunk-api-vs-gui-search-results.html.... However, I use the | stats count and results endpoint approach suggested by that answer. Also, even if the count was also being capped at 100000 events as happens with the eventCount property, the count is still far below 100000. Thus, my problem must have a different cause.

Thanks!

Tags (1)
0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...