<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data delay in events in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Data-delay-in-events/m-p/680815#M113745</link>
    <description>&lt;P&gt;Search for the events after they have arrived in Splunk&lt;/P&gt;</description>
    <pubDate>Fri, 15 Mar 2024 10:20:06 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2024-03-15T10:20:06Z</dc:date>
    <item>
      <title>Data delay in events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-delay-in-events/m-p/680273#M113668</link>
      <description>&lt;P&gt;Using props.conf i'm able to extract the fields but on the Splunk dashboard, the data is not visible for the timing 05:26 pm and data is visible for 05:27 pm, if i check after 2-3 minutes the entry at 05:26 pm will be visible. On the dashboard the default time is last 15 minutes.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2024 12:12:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-delay-in-events/m-p/680273#M113668</guid>
      <dc:creator>jahnavi</dc:creator>
      <dc:date>2024-03-11T12:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: Data delay in events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-delay-in-events/m-p/680276#M113670</link>
      <description>&lt;P&gt;Events are retrieved based on the value of _time, so depending on how your event is parsed, it may appear in the index retrospectively.&lt;/P&gt;&lt;P&gt;For example, Apache httpd log entries are usually timestamped with the time the request came in e.g. 05:26, but it is written to the log when the request is completed, for example, 05:28. This means that it was not in the log at 05:27, but did appear "later"&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2024 13:22:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-delay-in-events/m-p/680276#M113670</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-03-11T13:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: Data delay in events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-delay-in-events/m-p/680803#M113740</link>
      <description>&lt;P&gt;Thank you for your response.&lt;/P&gt;&lt;P&gt;Please may I know what would be the solution.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 08:29:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-delay-in-events/m-p/680803#M113740</guid>
      <dc:creator>jahnavi</dc:creator>
      <dc:date>2024-03-15T08:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: Data delay in events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-delay-in-events/m-p/680815#M113745</link>
      <description>&lt;P&gt;Search for the events after they have arrived in Splunk&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 10:20:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-delay-in-events/m-p/680815#M113745</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-03-15T10:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: Data delay in events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-delay-in-events/m-p/680823#M113746</link>
      <description>&lt;P&gt;Yes events have arrived but if I check in the graph for last 15 minutes, then few events are missing in last 5 minutes,is there any solution for this?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 11:55:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-delay-in-events/m-p/680823#M113746</guid>
      <dc:creator>jahnavi</dc:creator>
      <dc:date>2024-03-15T11:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: Data delay in events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-delay-in-events/m-p/680830#M113747</link>
      <description>&lt;P&gt;The short answer is probably no.&lt;/P&gt;&lt;P&gt;However, it may depend on your data, your applications doing the logging, your infrastructure, your networking, etc. None of this information is available to me. If there are delays built into any of these, there may be ways to work around them.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 12:19:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-delay-in-events/m-p/680830#M113747</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-03-15T12:19:41Z</dc:date>
    </item>
  </channel>
</rss>

