I am using Splunk 6.2.1 and I found a very disappointing match between chart count and actual search query count.
Queries in chart(42 Single value) and search box is exactly same.
Search query results are accurate but not the chart count in dashboard.
Used query is
... | search Call=C OR Call=U | search datetoday=Match | stats count
and lastly, the performance is worse as compared to previous versions. It's lagging.
Any help would be appreciated.
What is your full query? It seems that you may be able to merge all the filter conditions in one go and that should improve the performance.
Also, did you see what events are getting missed to cause the count difference?
last version of splunk have is unreliable Version.
me too i try some query with join and follows with appendcols command in 6.2.1. i have different result for 6.1.2 (correct one)
Tried 6.1.2, no luck