Dashboards & Visualizations

Dashboard refreshes with new data

mawg64
New Member

I have a dashboard panel that displays data using the preset of "Yesterday". But if I click refresh after a few seconds or minutes, I get a different result, it goes up by a few results everytime I refresh. If I run the same search with a date range it is the same. If I search using two days ago it doesnt change. In the timeline I can see that it is finding more events as the time moves towards the latter part of the day. Meaning at 1 PM on the first search only 267 events, 10 seconds wait, refresh 1 PM now has 296 events, 2 PM is completely empty and so on until I get tired of pushing refresh. This is historical data and should be constant. Any ideas?

Tags (1)
0 Karma

woodcock
Esteemed Legend

It is almost certainly that you have broken timestamping for your events and are accidentally throwing events into the past. So events that are indexed nowish and should be timestamped nowish, are being timestamped instead yesterdayish. It is also possible that the custody pipeline (which could be almost anything: ftp, syslog, etc.) contains something with a significant latency/delay and the events really are for yesterday but are arriving really late for indexing. There is not much you can do for the latter but both the Data Curator and Meta Woot apps will help you identify, qualify, quantify, and fix the broken timestamp problem if the former.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi mawg64,
I see only two choices:

  • you're still receiving old events, so it's correct that results are changing;
  • there's an error in time period definition.

If firsts you cannot do anything.
if second, verify time token and eventually share your code.

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...