I am trying to get a understanding why I get a different count total for the number of events for the following searches
1. index=some_specific_index (Returns the following total for events 7,601,134)
2. | tstats count where index=some_specific_index (Returns 7,593,248)
I do have the same date and time range sent when I run the query.
I understand why tstats and stats have different values.
In a general case, both
index=whatever | stats count
and
| tstats count where index=whatever
run over a static period of time in the past should give you the same result.
If there is a difference it might mean that you're still ingesting data into that period of time so subsequent runs of either of those commands will yield different results.
But if you have a repeatable two different static values of those searches it might signal bucket corruption.