Splunk Search

Why does adding a comment change the number of rows returned by a search?

bretlowery1
New Member

Using Splunk Enterprise 7.3.2 on a MacBook.
Two searches on the same static (loaded-once) search index, same date range, with or without other qualifiers return a different number of results when a comment is added vs when it is not.

See attached screenshots. With a comment returns 5 rows, without the (correct) 500K+ rows. What am I missing here?

alt text

0 Karma

woodcock
Esteemed Legend

You could figure this out if you tapped SHIFT-CTRL-E for Expand Macro and you would see that this reduced down to:

(index=* search)

which is incorrect. If you get rid of the search, it works as you would expect.

0 Karma

bretlowery1
New Member

alt text

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...