Splunk Search

Why is loadjob not getting all results?

michaelnorup
Communicator

Hi everyone.

I am trying to create historical capacity data over some servers. I have 1 search that will return all the data i need.
This search runs with a timepicker of 14 months(unlike the picture here for speed) and the last part ( | search Customer="*****") is not part of the scheduled report

michaelnorup_0-1679565513052.png

As you can see this returns 46 servers as expected.
Then, when i try to load the search later on to create dashboards it now only returns 23 servers...

michaelnorup_1-1679565627916.png
The fact that it returns SOME of the servers but not all is confusing me. I have triple checked that the Customer="***" is correct in both searches.

Does anybody have ideas? It makes no sense to me

 

 

Labels (1)
0 Karma

michaelnorup
Communicator

Anybody have ideas?

0 Karma

michaelnorup
Communicator

If i remove the dedup on servername in the second search (because its already there in the main search)
It disregards my time picker, and shows my data from the last 14 months i think

michaelnorup_0-1680001190980.png

 

0 Karma

Gr0und_Z3r0
Contributor

I can see an exclamation mark on the job for the first screenshot. You'll need to inspect the job for the scheduled search and see if there are any issues identified or indexers unable to provide results as part of the search execution.
Ensure that the scheduled searches always complete their executions and schedule them with correct priority.

0 Karma

michaelnorup
Communicator

There were no issues related to this unfortunately. And if there were issues in the first search, wouldnt that one also not be able to show all the results?

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...