<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does a real-time search with a small time range not return any results in Splunk 6.1.3? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-does-a-real-time-search-with-a-small-time-range-not-return/m-p/146028#M40750</link>
    <description>&lt;P&gt;Yes, this seems to make sense now.&lt;BR /&gt;
I had radial gauges in my real-time dashboards that showed the count of incoming events in a 1-minute window.&lt;BR /&gt;
It stopped working (always reporting zero) after I turned on DEBUG logging level on some application servers which increased incoming events from 1.5GB/day to about 36GB/day.&lt;/P&gt;

&lt;P&gt;I might have to look at clustering Splunk to process things faster if I want the 1-min real-time reporting?&lt;/P&gt;</description>
    <pubDate>Fri, 17 Apr 2015 18:23:33 GMT</pubDate>
    <dc:creator>nk-1</dc:creator>
    <dc:date>2015-04-17T18:23:33Z</dc:date>
    <item>
      <title>Why does a real-time search with a small time range not return any results in Splunk 6.1.3?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-a-real-time-search-with-a-small-time-range-not-return/m-p/146026#M40748</link>
      <description>&lt;P&gt;Sample Splunk Web search in Splunk 6.1.3 (Windows Server 2012):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host=MyHost level=INFO | stats count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;always returns zero if I use Real Time 1-minute window.&lt;BR /&gt;
If I change to Real Time 5-minute window, I get numbers that change every couple of seconds.&lt;/P&gt;

&lt;P&gt;Why won't the 1-minute real-time window return results?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2015 20:29:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-a-real-time-search-with-a-small-time-range-not-return/m-p/146026#M40748</guid>
      <dc:creator>nk-1</dc:creator>
      <dc:date>2015-04-16T20:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why does a real-time search with a small time range not return any results in Splunk 6.1.3?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-a-real-time-search-with-a-small-time-range-not-return/m-p/146027#M40749</link>
      <description>&lt;P&gt;Hi, When you simply do a ....|stats count ,splunk is doing statistics over all fields and that may take time so 1 minute window may be not be sufficient for that.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2015 20:47:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-a-real-time-search-with-a-small-time-range-not-return/m-p/146027#M40749</guid>
      <dc:creator>stephane_cyrill</dc:creator>
      <dc:date>2015-04-16T20:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: Why does a real-time search with a small time range not return any results in Splunk 6.1.3?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-a-real-time-search-with-a-small-time-range-not-return/m-p/146028#M40750</link>
      <description>&lt;P&gt;Yes, this seems to make sense now.&lt;BR /&gt;
I had radial gauges in my real-time dashboards that showed the count of incoming events in a 1-minute window.&lt;BR /&gt;
It stopped working (always reporting zero) after I turned on DEBUG logging level on some application servers which increased incoming events from 1.5GB/day to about 36GB/day.&lt;/P&gt;

&lt;P&gt;I might have to look at clustering Splunk to process things faster if I want the 1-min real-time reporting?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2015 18:23:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-a-real-time-search-with-a-small-time-range-not-return/m-p/146028#M40750</guid>
      <dc:creator>nk-1</dc:creator>
      <dc:date>2015-04-17T18:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why does a real-time search with a small time range not return any results in Splunk 6.1.3?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-a-real-time-search-with-a-small-time-range-not-return/m-p/146029#M40751</link>
      <description>&lt;P&gt;Hi nk-1, feel free to vote and accept the answer. thanks&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2015 23:46:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-a-real-time-search-with-a-small-time-range-not-return/m-p/146029#M40751</guid>
      <dc:creator>stephane_cyrill</dc:creator>
      <dc:date>2015-04-17T23:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why does a real-time search with a small time range not return any results in Splunk 6.1.3?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-a-real-time-search-with-a-small-time-range-not-return/m-p/146030#M40752</link>
      <description>&lt;P&gt;I'd just like to add a note that a reason why my 1-minute real-time window was not producing results when I went from indexing 1.5GB/day to 36GB/day was because the forwarders sending events to my indexers were, by default, configured to throttle after 256KB/second.&lt;BR /&gt;
I changed maxKBps in limits.conf to zero in the forwarders, and the 1-minute real-time window displays updating counts now, without the need for clustering.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2015 15:25:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-a-real-time-search-with-a-small-time-range-not-return/m-p/146030#M40752</guid>
      <dc:creator>nk-1</dc:creator>
      <dc:date>2015-04-21T15:25:18Z</dc:date>
    </item>
  </channel>
</rss>

