Hello Everyone, I am new to the splunk and this community. I have searched everyone for my problem but i could not figure out what is wrong. Basically i am using base search and post process search for a dashboard. My base search is something like this: <search id="basesearch1">
<query>index=index1 | fields field1, field2</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search> my second base search that uses first base search: <search base="basesearch1" id="basesearch2">
<query>search field1=value1</query>
</search> and finally the post process search is: <search base="basesearch2">
<query>stats count(field1) as count by field2 | sort -count | head 5</query>
</search> When i apply it as a single search query like this there is no problem: index=index1 | fields field1, field2 | search field1=value1 | stats count(field1) as count by field2 | sort -count | head 5 however, in the dashboard the count numbers does not match with the above search query. I used 2 base searches because in the same dashboard, I need to use basesearch1 and basesearch2 in different panels as well.
... View more