Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

Mismatch search result between sdk-python and splunk web

$
0
0

Hi, i'm just learning using splunk and sdk-python. I have this search run from sdk:

search = 'search index=main sourcetype=syslog | search *ERROR* | stats count by process' params = {"earliest_time" : "-30d", "latest_time" : "now", "exec_mode" : "blocking", "auto_cancel" : 600 }

And i get this result:

<?xml version='1.0' encoding='UTF-8'?> <results preview='0'> <meta> <fieldOrder> <field>process</field> <field>count</field> </fieldOrder> </meta> <result offset='0'> <field k='process'> <value><text>dbus</text></value> </field> <field k='count'> <value><text>4</text></value> </field> </result> <result offset='1'> <field k='process'> <value><text>kernel</text></value> </field> <field k='count'> <value><text>10</text></value> </field> </result> </results>

If i run the same search from splunk web, i get the following result:

<?xml version='1.0' encoding='UTF-8'?> <results preview='0'> <meta> <fieldOrder> <field>process</field> <field>count</field> </fieldOrder> </meta> <result offset='0'> <field k='process'> <value><text>dbus</text></value> </field> <field k='count'> <value><text>4</text></value> </field> </result> <result offset='1'> <field k='process'> <value><text>kernel</text></value> </field> <field k='count'> <value><text>17</text></value> </field> </result> </results>

So in the first result count for process kernel is 10, in the second is 17. Why? Could be for the exec_mode of search in python-sdk? Thanks.


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>