All Apps and Add-ons

TrackMe - Last Event / Last Time not updating

willadams
Contributor

First up, awesome tool and really useful.  I am new to the tool and learning the intricacies of it, however I have come across a problem that I don't quite understand yet.  I ran the "Run: Trackers Report" and used the short term tracker.  This populated the information I need for all my data sources and shows the last time, last ingest and last time idx fields which I then matched against a search run in SPL.  However I have noted that while the index is updating (via SPL), TrackMe is not reflecting this in these columns.  For example

* Run Tracker --> last time, last ingest and last time idx are showing as 10/12/2020 11:59.  The data_max_allowed is default of 3600 currently

Come back later and let the application refresh and checking the index using SPL I can see that the index has updated with a few new events so fr arguments sake the index now has a recent event at 10/12/2020 12:35

* However in the TrackMe application (no manual run of the Trackers reports), the last time, last ingest and last time idx are showing as 10/12/2020 11:59 is not reflective of this.

 

Do I need to wait for the "max_lag_allowed" to expire before it refreshes these fields?  I assumed this is automated without having to manual run the trackers constantly.  

Labels (1)
Tags (1)
0 Karma
1 Solution

willadams
Contributor

I think I answered my own question.  There is a search that is not scheduled to run.  Obvious answer is to set a schedule and let it run as and when required.  

View solution in original post

0 Karma

willadams
Contributor

Hi @guilmxm, thanks for the reply.  I went into the scheduled task and saw that it was a scheduled job.  It seemed that for whatever reason (running this on 7.2.9.1) that I simply had to disable the schedule, save it and re-enable afterwards.  Worked a treat.  

0 Karma

willadams
Contributor

I think I answered my own question.  There is a search that is not scheduled to run.  Obvious answer is to set a schedule and let it run as and when required.  

0 Karma

guilmxm
Influencer

Hi @willadams 

By defaut, the reports handling and maintaining the update of these information in the KVstore collections are enabed and scheduled, you may have had something disabling it somehow during your deployment, or someone else did.

Let me know if you face any further issue.

Guilhem

0 Karma
Get Updates on the Splunk Community!

Security Highlights: September 2022 Newsletter

 September 2022 The Splunk App for Fraud Analytics (SFA) is now Splunk SupportedUse your existing Splunk ...

Platform Highlights | September 2022 Newsletter

 September 2022 What’s New in 9.0 and How to UpgradeGet a walk through of what is new Splunk Enterprise 9.0 ...

Observability Highlights | September 2022 Newsletter

 September 2022 Splunk Observability SuiteAccess to "Classic" SignalFx Interface Will be Removed on Sept 30, ...