Hi.
A site we are on has attemtped to migrate data from one splunk cluster to another. We've come in late to help and have fixed most things up but they are noticing a difference in their eventcount type searches and real event searches. So `index=* | stats count by index` gives one set of numbers but `eventcount summarize=false index=*` gives quite different numbers, an amount less.
I'm thinking the metadata values have been messed up during their copy activities and wonder if they can be rebuilt?
Thanks.
↧