Dashboards & Visualizations

Dashboard refreshes with new data

mawg64
New Member

I have a dashboard panel that displays data using the preset of "Yesterday". But if I click refresh after a few seconds or minutes, I get a different result, it goes up by a few results everytime I refresh. If I run the same search with a date range it is the same. If I search using two days ago it doesnt change. In the timeline I can see that it is finding more events as the time moves towards the latter part of the day. Meaning at 1 PM on the first search only 267 events, 10 seconds wait, refresh 1 PM now has 296 events, 2 PM is completely empty and so on until I get tired of pushing refresh. This is historical data and should be constant. Any ideas?

Tags (1)
0 Karma

woodcock
Esteemed Legend

It is almost certainly that you have broken timestamping for your events and are accidentally throwing events into the past. So events that are indexed nowish and should be timestamped nowish, are being timestamped instead yesterdayish. It is also possible that the custody pipeline (which could be almost anything: ftp, syslog, etc.) contains something with a significant latency/delay and the events really are for yesterday but are arriving really late for indexing. There is not much you can do for the latter but both the Data Curator and Meta Woot apps will help you identify, qualify, quantify, and fix the broken timestamp problem if the former.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi mawg64,
I see only two choices:

  • you're still receiving old events, so it's correct that results are changing;
  • there's an error in time period definition.

If firsts you cannot do anything.
if second, verify time token and eventually share your code.

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...