Using docker splunk logging driver to push logs to splunk, but noticed time lag in the log creation and event availability in splunk.
Is there a way to reduce the time lag? Is this because of the indexing time or log transfer or both?
The Troubleshooting Manual has a specific section on event indexing delays, which includes identifying the cause.
http://docs.splunk.com/Documentation/Splunk/6.5.3/Troubleshooting/Troubleshootingeventsindexingdelay