Dashboards & Visualizations

How to quickly update transaction count on a dashboard?

randymoore
Explorer

Hello everyone,

We have a dashboard that displays the number of transactions for the day, as a single value panel. The search is very simple and easy as each transaction is a separate event in the log:

index=my_index category=transaction | stats count

The dashboard refreshes every 5 minutes. Which means that Splunk recounts them every 5 minutes to come up with the new count. What happens is that during our busy time of the year, the number of transactions arriving exceed 5 minute refresh time it takes Splunk to finish counting them.

What I would love is for Splunk to “remember” the last count of transactions (say it was 7,500,000) and start counting from there. That way, the count is accurate, and the Splunk processing is not as great (hopefully).

I just don’t know how to do that, or if it can be done. Any ideas?

0 Karma
1 Solution

sundareshr
Legend

nravichandran
Communicator

One of the option could be to use KV Store to Persist data, but for that particular session.

0 Karma

randymoore
Explorer

Looking into that next. Will update by the begining of next week hopefully.

0 Karma

sundareshr
Legend

Have you looked at Accelerated Reports?

randymoore
Explorer

Thanks for the pointer to Accelerated Reports. I enabled that for the dashboard panel. I'll time it over the next few days to see if it works as I expect.

0 Karma

randymoore
Explorer

Ran a stress test and using Accelerated Reports worked like I wanted it to. Thanks!

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...