Hello.
Recently I met a problem. I found that a number of events are different between the database and the search.
I confirmed that the number of events was correct when I connected the database(picture1 in attachment).
However, when I found events in DB connect, the number of events was much more bigger than in the DB.
I further checked the events and found out that some events in the database were imported into Splunk more than once(some twice, some triple).
So the number of events in Splunk is bigger than in the database.
Furthermore, when Splunk first connected with the database, the number of events was correct in Splunk.
But maybe, after several days, the number became wrong. Could someone tell me what is the reason?
Thank you so much!
... View more