All Apps and Add-ons

TrackMe - Last Event / Last Time not updating

willadams
Contributor

First up, awesome tool and really useful.  I am new to the tool and learning the intricacies of it, however I have come across a problem that I don't quite understand yet.  I ran the "Run: Trackers Report" and used the short term tracker.  This populated the information I need for all my data sources and shows the last time, last ingest and last time idx fields which I then matched against a search run in SPL.  However I have noted that while the index is updating (via SPL), TrackMe is not reflecting this in these columns.  For example

* Run Tracker --> last time, last ingest and last time idx are showing as 10/12/2020 11:59.  The data_max_allowed is default of 3600 currently

Come back later and let the application refresh and checking the index using SPL I can see that the index has updated with a few new events so fr arguments sake the index now has a recent event at 10/12/2020 12:35

* However in the TrackMe application (no manual run of the Trackers reports), the last time, last ingest and last time idx are showing as 10/12/2020 11:59 is not reflective of this.

 

Do I need to wait for the "max_lag_allowed" to expire before it refreshes these fields?  I assumed this is automated without having to manual run the trackers constantly.  

Labels (1)
Tags (1)
0 Karma
1 Solution

willadams
Contributor

I think I answered my own question.  There is a search that is not scheduled to run.  Obvious answer is to set a schedule and let it run as and when required.  

View solution in original post

0 Karma

willadams
Contributor

Hi @guilmxm, thanks for the reply.  I went into the scheduled task and saw that it was a scheduled job.  It seemed that for whatever reason (running this on 7.2.9.1) that I simply had to disable the schedule, save it and re-enable afterwards.  Worked a treat.  

0 Karma

willadams
Contributor

I think I answered my own question.  There is a search that is not scheduled to run.  Obvious answer is to set a schedule and let it run as and when required.  

0 Karma

guilmxm
SplunkTrust
SplunkTrust

Hi @willadams 

By defaut, the reports handling and maintaining the update of these information in the KVstore collections are enabed and scheduled, you may have had something disabling it somehow during your deployment, or someone else did.

Let me know if you face any further issue.

Guilhem

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...