- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Using docker splunk driver, has time lag in events available for search
swetha521
New Member
04-12-2017
03:22 AM
Using docker splunk logging driver to push logs to splunk, but noticed time lag in the log creation and event availability in splunk.
Is there a way to reduce the time lag? Is this because of the indexing time or log transfer or both?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

hmallett
Path Finder
04-12-2017
04:52 AM
The Troubleshooting Manual has a specific section on event indexing delays, which includes identifying the cause.
http://docs.splunk.com/Documentation/Splunk/6.5.3/Troubleshooting/Troubleshootingeventsindexingdelay
