Hi, i'm just learning using splunk and sdk-python. I have this search run from sdk:
search = 'search index=main sourcetype=syslog | search *ERROR* | stats count by process'
params = {"earliest_time" : "-30d", "latest_time" : "now", "exec_mode" : "blocking", "auto_cancel" : 600 }
And i get this result:
<?xml version='1.0' encoding='UTF-8'?>
<results preview='0'>
<meta>
<fieldOrder>
<field>process</field>
<field>count</field>
</fieldOrder>
</meta>
<result offset='0'>
<field k='process'>
<value><text>dbus</text></value>
</field>
<field k='count'>
<value><text>4</text></value>
</field>
</result>
<result offset='1'>
<field k='process'>
<value><text>kernel</text></value>
</field>
<field k='count'>
<value><text>10</text></value>
</field>
</result>
</results>
If i run the same search from splunk web, i get the following result:
<?xml version='1.0' encoding='UTF-8'?>
<results preview='0'>
<meta>
<fieldOrder>
<field>process</field>
<field>count</field>
</fieldOrder>
</meta>
<result offset='0'>
<field k='process'>
<value><text>dbus</text></value>
</field>
<field k='count'>
<value><text>4</text></value>
</field>
</result>
<result offset='1'>
<field k='process'>
<value><text>kernel</text></value>
</field>
<field k='count'>
<value><text>17</text></value>
</field>
</result>
</results>
So in the first result count for process kernel is 10, in the second is 17. Why? Could be for the exec_mode of search in python-sdk? Thanks.