Splunk version 5.0.1
Recently I'm getting strange results in my reports.
Although the result tables shows all events until now the last 30-day report only shows results until 30 Mar 21:30.
When changing the 15m span to a span of 30m I do get the correct results.
When playing with a span shorter than 23m the report varies but never displays all results until now.
Is this a bug in Splunk or am I doing something wrong?
The search :
index="dhcpstats" | fields Network, Leases, TotalLeases | timechart span=15m max(Leases) by Network
The csv source :
Time,Leases,Network,TotalLeases
201304010845,730,10.0.0.0/24,1008
201304010900,720,10.0.0.0/24,1008
201304010915,640,10.0.0.0/24,1008
201304010930,756,10.0.0.0/24,1008
201304010945,798,10.0.0.0/24,1008
201304011000,800,10.0.0.0/24,1008
... View more