I extracted sample data from our prod instance of Splunk to be used in the test instance. The way I did it was to run a search in prod instance, export the results to CSV and then upload into test instance. Everything seems so to correct the data except the timeendpos and timestart pos values.
Some how on the test instance the timeendpos and timestartpos seem to have two sets values for each row of data.
If I run the following query
index=xyz user="john" | table user, date_hour, date_minute, timestartpos, timeendpos
In prod it returns
john 16 33 10 24
but the same query on test returns
john 16 33 10 24
blank 16 33 92 102
So loading the data in test seems to have introduced extra values for timestartpos and timeendpos, 92 and 102 respectively.
Unfortunately, I can't post a properly formatted output.
Does anyone know why this is happening and how to resolve the issue?
... View more