@pop1989 , could you please answer the questions others have asked? Are you running the search on an absolute time range?
Hi pop1989
I think that your problem is caused by the data which are non stable , if your data come continuously into splunk , it is evident that the results change.
To verify this approach , specify a time range for you request . And let analyse your search result.
Is the data coming to Splunk continuously? Are you using Time ranges like 'Last 4 Hrs' OR 'Since <>'? If yes than The time range is getting changed every time you run the search, causing search result to be different.
hi Pop,
Hope you are not running the search for AllTime, as in AllTime along with events the time value also gets changed.
Kindly confirm by running the search query for specific time range.