You applied a time filter as during Thu, Dec 7, 2023. Why did you apply a time filter in the Splunk search? If you select the “All time” option, it will display all requests. Since all these logs are access log entries, they are all web requests, so there’s no need to filter by HTTP/1.1.
It is showing a value higher than the expected result. After verifying the answer by checking newline count of the log file, you can check what might be going wrong within Splunk