I have a dashboard panel that displays data using the preset of "Yesterday". But if I click refresh after a few seconds or minutes, I get a different result, it goes up by a few results everytime I refresh. If I run the same search with a date range it is the same. If I search using two days ago it doesnt change. In the timeline I can see that it is finding more events as the time moves towards the latter part of the day. Meaning at 1 PM on the first search only 267 events, 10 seconds wait, refresh 1 PM now has 296 events, 2 PM is completely empty and so on until I get tired of pushing refresh. This is historical data and should be constant. Any ideas?
It is almost certainly that you have broken timestamping for your events and are accidentally throwing events into the past. So events that are indexed nowish and should be timestamped nowish, are being timestamped instead yesterdayish. It is also possible that the custody pipeline (which could be almost anything: ftp, syslog, etc.) contains something with a significant latency/delay and the events really are for yesterday but are arriving really late for indexing. There is not much you can do for the latter but both the Data Curator
and Meta Woot
apps will help you identify, qualify, quantify, and fix the broken timestamp problem if the former.
Hi mawg64,
I see only two choices:
If firsts you cannot do anything.
if second, verify time token and eventually share your code.
Bye.
Giuseppe