Splunk Search

Why is performance worse in Splunk 6.2.1 and the results are different between dashboard chart count and actual search query count?

asifhj
Path Finder

Hi Splunkers,

I am using Splunk 6.2.1 and I found a very disappointing match between chart count and actual search query count.

Queries in chart(42 Single value) and search box is exactly same.

Search query results are accurate but not the chart count in dashboard.

Used query is

... | search Call=C OR Call=U | search datetoday=Match | stats count

and lastly, the performance is worse as compared to previous versions. It's lagging.

Any help would be appreciated.

0 Karma

somesoni2
Revered Legend

What is your full query? It seems that you may be able to merge all the filter conditions in one go and that should improve the performance.
Also, did you see what events are getting missed to cause the count difference?

0 Karma

tachifelix
Path Finder

last version of splunk have is unreliable Version.
me too i try some query with join and follows with appendcols command in 6.2.1. i have different result for 6.1.2 (correct one)

0 Karma

asifhj
Path Finder

Tried 6.1.2, no luck

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...