Dashboards & Visualizations

Dashboard refreshes with new data

mawg64
New Member

I have a dashboard panel that displays data using the preset of "Yesterday". But if I click refresh after a few seconds or minutes, I get a different result, it goes up by a few results everytime I refresh. If I run the same search with a date range it is the same. If I search using two days ago it doesnt change. In the timeline I can see that it is finding more events as the time moves towards the latter part of the day. Meaning at 1 PM on the first search only 267 events, 10 seconds wait, refresh 1 PM now has 296 events, 2 PM is completely empty and so on until I get tired of pushing refresh. This is historical data and should be constant. Any ideas?

Tags (1)
0 Karma

woodcock
Esteemed Legend

It is almost certainly that you have broken timestamping for your events and are accidentally throwing events into the past. So events that are indexed nowish and should be timestamped nowish, are being timestamped instead yesterdayish. It is also possible that the custody pipeline (which could be almost anything: ftp, syslog, etc.) contains something with a significant latency/delay and the events really are for yesterday but are arriving really late for indexing. There is not much you can do for the latter but both the Data Curator and Meta Woot apps will help you identify, qualify, quantify, and fix the broken timestamp problem if the former.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi mawg64,
I see only two choices:

  • you're still receiving old events, so it's correct that results are changing;
  • there's an error in time period definition.

If firsts you cannot do anything.
if second, verify time token and eventually share your code.

Bye.
Giuseppe

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...