Make sure you are running both searches in the same time range. Otherwise, I don't see any reason for them to show different results. how can I search for all the increments of the source if I know what it is? * You can use the search with metadata command. * But you generally don't need it because Splunk will always monitor tortor-adaptor.log file not the rolled over filed (tortor-adaptor.log.1, tortor-adaptor.log.2, etc) * So when you start logging for the first time only at that time it will monitor rolled-over files.
... View more