Dashboards & Visualizations

Dashboard refreshes with new data

mawg64
New Member

I have a dashboard panel that displays data using the preset of "Yesterday". But if I click refresh after a few seconds or minutes, I get a different result, it goes up by a few results everytime I refresh. If I run the same search with a date range it is the same. If I search using two days ago it doesnt change. In the timeline I can see that it is finding more events as the time moves towards the latter part of the day. Meaning at 1 PM on the first search only 267 events, 10 seconds wait, refresh 1 PM now has 296 events, 2 PM is completely empty and so on until I get tired of pushing refresh. This is historical data and should be constant. Any ideas?

Tags (1)
0 Karma

woodcock
Esteemed Legend

It is almost certainly that you have broken timestamping for your events and are accidentally throwing events into the past. So events that are indexed nowish and should be timestamped nowish, are being timestamped instead yesterdayish. It is also possible that the custody pipeline (which could be almost anything: ftp, syslog, etc.) contains something with a significant latency/delay and the events really are for yesterday but are arriving really late for indexing. There is not much you can do for the latter but both the Data Curator and Meta Woot apps will help you identify, qualify, quantify, and fix the broken timestamp problem if the former.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi mawg64,
I see only two choices:

  • you're still receiving old events, so it's correct that results are changing;
  • there's an error in time period definition.

If firsts you cannot do anything.
if second, verify time token and eventually share your code.

Bye.
Giuseppe

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...