Splunk Search

Why is the same search returning different results each time it is run?

pop1989
Explorer

I use Splunk to calculate user's Internet hits. There are about 710 thousands entries. I searched several times, but the results are different. Does anyone know why this happens?

Tags (2)
0 Karma

rey123
Path Finder

@pop1989 , could you please answer the questions others have asked? Are you running the search on an absolute time range?

0 Karma

chimell
Motivator

Hi pop1989
I think that your problem is caused by the data which are non stable , if your data come continuously into splunk , it is evident that the results change.
To verify this approach , specify a time range for you request . And let analyse your search result.

0 Karma

somesoni2
Revered Legend

Is the data coming to Splunk continuously? Are you using Time ranges like 'Last 4 Hrs' OR 'Since <>'? If yes than The time range is getting changed every time you run the search, causing search result to be different.

0 Karma

neelamssantosh
Contributor

hi Pop,

Hope you are not running the search for AllTime, as in AllTime along with events the time value also gets changed.

Kindly confirm by running the search query for specific time range.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...