Splunk Search

incomprehensible value of Scancount

New Member


I have this SPL request in a search :

index=<my_index> (url_host="yqe-tractors.stenchkrzl.xyz" OR
url_host="stereotype.gumpzzyr.xyz" OR
url_host="tribes.mugsylhb.xyz" OR
url_host="taken-uprisings.coveringsiqnh.xyz" OR
url_host="unmarried.discussedya.xyp") | stats count by url_host

When I launch this request, in the job inspector I have a value for the scanCount.

When I modify my request by changing the extension "xyz" on any line of my request (by example with "org"), my scanCount value is None.

can Anyone explain me why the scanCount value is None when I modify the extension in one line of my request (example by replacing "xyz" by "org" in one line) ?

In my index I have more than 500 millions events for the last 30 days.
I am surprised, when I launch my request (same request as above) for the last 30 days, The search completed in 5 seconds whitout no results.
For me even if they are no results, as I have millions of events, Splunk will take more time to scan the millions of events and show the result. Am i wrong?


0 Karma
Get Updates on the Splunk Community!

Index This | A sphere has three, a circle has two, and a point has zero. What is it?

September 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...