Splunk Search

Why is the same search returning different results each time it is run?

pop1989
Explorer

I use Splunk to calculate user's Internet hits. There are about 710 thousands entries. I searched several times, but the results are different. Does anyone know why this happens?

Tags (2)
0 Karma

rey123
Path Finder

@pop1989 , could you please answer the questions others have asked? Are you running the search on an absolute time range?

0 Karma

chimell
Motivator

Hi pop1989
I think that your problem is caused by the data which are non stable , if your data come continuously into splunk , it is evident that the results change.
To verify this approach , specify a time range for you request . And let analyse your search result.

0 Karma

somesoni2
Revered Legend

Is the data coming to Splunk continuously? Are you using Time ranges like 'Last 4 Hrs' OR 'Since <>'? If yes than The time range is getting changed every time you run the search, causing search result to be different.

0 Karma

neelamssantosh
Contributor

hi Pop,

Hope you are not running the search for AllTime, as in AllTime along with events the time value also gets changed.

Kindly confirm by running the search query for specific time range.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...