Splunk Search

Why does adding a comment change the number of rows returned by a search?

bretlowery1
New Member

Using Splunk Enterprise 7.3.2 on a MacBook.
Two searches on the same static (loaded-once) search index, same date range, with or without other qualifiers return a different number of results when a comment is added vs when it is not.

See attached screenshots. With a comment returns 5 rows, without the (correct) 500K+ rows. What am I missing here?

alt text

0 Karma

woodcock
Esteemed Legend

You could figure this out if you tapped SHIFT-CTRL-E for Expand Macro and you would see that this reduced down to:

(index=* search)

which is incorrect. If you get rid of the search, it works as you would expect.

0 Karma

bretlowery1
New Member

alt text

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...