Splunk Search

Why does adding a comment change the number of rows returned by a search?

bretlowery1
New Member

Using Splunk Enterprise 7.3.2 on a MacBook.
Two searches on the same static (loaded-once) search index, same date range, with or without other qualifiers return a different number of results when a comment is added vs when it is not.

See attached screenshots. With a comment returns 5 rows, without the (correct) 500K+ rows. What am I missing here?

alt text

0 Karma

woodcock
Esteemed Legend

You could figure this out if you tapped SHIFT-CTRL-E for Expand Macro and you would see that this reduced down to:

(index=* search)

which is incorrect. If you get rid of the search, it works as you would expect.

0 Karma

bretlowery1
New Member

alt text

0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...