Hello,
I am having trouble understanding why the counts for a particular field are off. The time frames for both the screenshots below are the same. The only difference is the view for the results.
The first screenshot says the count for namespace field "example" is 261,158 and the search used was:
index=network
The second screenshot says the count for namespace field "example" is 435 and the search used was:
index=network namespace=example
You can see that there is a drastic difference in "count" for the namespace field "example".
Thoughts?
What happens if you add this before your stats? I suspect it may be making some assumptions when the namespace field is null.
| eval namespace=case(isnotnull(namespace),namespace)
Does | stats dc(namespace) also produce erroneous results?
What happens if you add this before your stats? I suspect it may be making some assumptions when the namespace field is null.
| eval namespace=case(isnotnull(namespace),namespace)
Does | stats dc(namespace) also produce erroneous results?
Apologies, the eval command worked and showed me the where the rest of the count was coming from.
Thank you for your help!