Splunk Search

tstats not match with metrics.log

new2spl_unk
Explorer

Hi all,

Why the count of  "Event per day" in the "Indexing audit" dashboard is not match with |tstats result? 

Eg.

The number from  "Event per day" in the "Indexing audit" dashboard:

index count 

main 10000

 

The number from |tstats count where index=main by index:

index count 

main 500

 

May I know which one is correct?

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's possible both are correct. Or neither is correct.  The two use different methods to arrive at numbers that may or may not represent the same thing.  Also, we don't know the time window of each search.

The Indexing Audit dashboard uses a lookup table which is populated by a saved search.  That search pulls data from metrics.log, which is a sampling of events rather than a true count.

The tstats query is counting actual events present in the index at the time the query runs.

---
If this reply helps you, Karma would be appreciated.
0 Karma

new2spl_unk
Explorer

Assume the time window is same. But from my environment,

the count from indexing audit dashboard is always 4-5 times more than the result from |tstats. If I want to know the Event per day. Which method is more accurate? 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

tstats is a count of all events whereas the Indexing Audit dashboard counts a sample of events.  I would say tstats is more accurate.

---
If this reply helps you, Karma would be appreciated.
0 Karma

new2spl_unk
Explorer

Thanks for your response. Can you explain more on  the "Indexing Audit dashboard" like how it counts the event count exactly. As it count on sample of event then the count should lower than |tstats count? Then why my "Indexing Audit dashboard" always 4-5 times higher than |tstats count ? 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The dashboard gets its data from a KVStore lookup (licensing_epd).  If the data in that lookup is inaccurate then so will the dashboard.  See the Audit - Events Per Day - Lookup Gen saved search for how the lookup is populated.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...