All Apps and Add-ons

Using docker splunk driver, has time lag in events available for search

swetha521
New Member

Using docker splunk logging driver to push logs to splunk, but noticed time lag in the log creation and event availability in splunk.
Is there a way to reduce the time lag? Is this because of the indexing time or log transfer or both?

Tags (1)
0 Karma

hmallett
Path Finder

The Troubleshooting Manual has a specific section on event indexing delays, which includes identifying the cause.

http://docs.splunk.com/Documentation/Splunk/6.5.3/Troubleshooting/Troubleshootingeventsindexingdelay

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...