Splunk timechart discrepancy

30 views Asked by At

Exact search query that has timechart results by span on 1 hour brings different values with different Date time range (Search through standard time picker). For example, if I provide exact hour window in the picker (4:00:00-5:00:00), I get exact results like 8000 count, but if I provide three hour time window (4:00:00-7:00:00), the values for each hour breakdown are little lesser than earlier ones, like showing 7400 count for same 4-5 hour window. Kindly help understand what is going wrong with timechart search query? Also tried with partial=f which is reducing difference just a little bit but still the results are falling short, so not much help with this option.

0

There are 0 answers