<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stats table not updating real time in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Stats-table-not-updating-real-time/m-p/123162#M33248</link>
    <description>&lt;P&gt;Your second idea could actually be true; I've found it hard to deal with searches returning no results using the splunk js stack as well. I'm going to see if I can figure this out with some example.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Jul 2015 08:16:51 GMT</pubDate>
    <dc:creator>jeffland</dc:creator>
    <dc:date>2015-07-15T08:16:51Z</dc:date>
    <item>
      <title>Stats table not updating real time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Stats-table-not-updating-real-time/m-p/123158#M33244</link>
      <description>&lt;P&gt;Hi. I have this table.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://i.imgur.com/gvKjxXq.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;As you can see there are 2 storeA in both normal and critical. The latest record is on the normal table. I use this &lt;CODE&gt;| where CPU_Load &amp;amp;lt; 1 AND Processes &amp;amp;lt; 99&lt;/CODE&gt; for the normal table and different conditions on the other panels. I dont know what is the problem in here but it looks like the table itself is not updating real time! Can someone help me in here?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2015 07:44:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Stats-table-not-updating-real-time/m-p/123158#M33244</guid>
      <dc:creator>josefa123</dc:creator>
      <dc:date>2015-07-15T07:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: Stats table not updating real time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Stats-table-not-updating-real-time/m-p/123159#M33245</link>
      <description>&lt;P&gt;I'd say that in the time range that these searches run on, there are records for both a CPU load above and below your thresholds. Maybe you should make your table show averages, that would make them show up in only one of your tables.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2015 07:55:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Stats-table-not-updating-real-time/m-p/123159#M33245</guid>
      <dc:creator>jeffland</dc:creator>
      <dc:date>2015-07-15T07:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: Stats table not updating real time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Stats-table-not-updating-real-time/m-p/123160#M33246</link>
      <description>&lt;P&gt;if that's the case it would be easy. But I already configured every event to every minute and real time to a 1 minute window. i think the culprit here is that when the search triggers and the panel detects that it is not on the condition, it wont update the table so the last record was still there remaining.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2015 08:02:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Stats-table-not-updating-real-time/m-p/123160#M33246</guid>
      <dc:creator>josefa123</dc:creator>
      <dc:date>2015-07-15T08:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: Stats table not updating real time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Stats-table-not-updating-real-time/m-p/123161#M33247</link>
      <description>&lt;P&gt;OR another theory is that tables or stats doesn't return empty record so it retains the last record it has to show.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2015 08:08:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Stats-table-not-updating-real-time/m-p/123161#M33247</guid>
      <dc:creator>josefa123</dc:creator>
      <dc:date>2015-07-15T08:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: Stats table not updating real time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Stats-table-not-updating-real-time/m-p/123162#M33248</link>
      <description>&lt;P&gt;Your second idea could actually be true; I've found it hard to deal with searches returning no results using the splunk js stack as well. I'm going to see if I can figure this out with some example.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2015 08:16:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Stats-table-not-updating-real-time/m-p/123162#M33248</guid>
      <dc:creator>jeffland</dc:creator>
      <dc:date>2015-07-15T08:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: Stats table not updating real time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Stats-table-not-updating-real-time/m-p/123163#M33249</link>
      <description>&lt;P&gt;I can confirm that tables based on real time searches which once had a result in their time range keep that last result once the time range moves ahead of that event, so that a table based on a real time search will always show the last result even if it has moved out of the time range of the real time search.&lt;/P&gt;

&lt;P&gt;Not sure if this is a bug or a feature &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;To solve your issue, you could convert your searches to regular searches and re-run them every minute or so.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2015 08:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Stats-table-not-updating-real-time/m-p/123163#M33249</guid>
      <dc:creator>jeffland</dc:creator>
      <dc:date>2015-07-15T08:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: Stats table not updating real time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Stats-table-not-updating-real-time/m-p/123164#M33250</link>
      <description>&lt;P&gt;can you elaborate more on this? "you could convert your searches to regular searches and re-run them every minute or so."&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2015 10:50:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Stats-table-not-updating-real-time/m-p/123164#M33250</guid>
      <dc:creator>josefa123</dc:creator>
      <dc:date>2015-07-15T10:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: Stats table not updating real time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Stats-table-not-updating-real-time/m-p/123165#M33251</link>
      <description>&lt;P&gt;Have your dashboard use normal searches, i.e. searches with the same time range but not as real time searches, and trigger them to refresh every minute:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;option name="refresh.auto.interval"&amp;gt;60&amp;lt;/option&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;See &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.4/Viz/PanelreferenceforSimplifiedXML#Panel_visualization_elements"&gt;here&lt;/A&gt; for docs.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2015 11:18:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Stats-table-not-updating-real-time/m-p/123165#M33251</guid>
      <dc:creator>jeffland</dc:creator>
      <dc:date>2015-07-15T11:18:13Z</dc:date>
    </item>
  </channel>
</rss>

