Dashboards & Visualizations

Why is my dashboard panel not updating with latest data?

ViewCelia
New Member

Hey everyone,

I’m working on a Splunk dashboard where one of the panels is supposed to show real-time logins from a specific source. The search runs fine when I do it manually in the search bar, but when it’s in the dashboard panel, it doesn’t seem to update properly unless I refresh the whole page.

The time picker is set to "Last 15 minutes (real-time)" and the auto-refresh is on, but the panel still gets stuck with old data sometimes. Has anyone run into something like this before? Could it be a refresh interval issue or something in the panel settings I’m missing?

Thanks in advance for any tips!

Spoiler

Looking to enhance the durability and appearance of your concrete surfaces? Contact Concrete Contractors Richmond VA today for expert concrete lifting, repair, and resurfacing services! Get your free estimate now!

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @ViewCelia

Dashboard panels with "real-time" time ranges can sometimes stall due to browser resource limits or Splunk server load. Switching from real-time to a short rolling window (e.g., "Last 15 minutes") with a scheduled refresh often improves reliability.

Set the panel search to "Last 15 minutes" (relative time, not real-time), then configure the dashboard or panel to auto-refresh every 1 minute.

This approach fetches recent data on each refresh instead of relying on continuous real-time streaming.

Real-time searches consume more resources and can be less stable in dashboards. Use scheduled refreshes with relative time for better performance. 

Check out the following docs page about realtime searches (https://docs.splunk.com/Documentation/Splunk/9.4.1/Search/Realtimeperformanceandlimitations#:~:text=...

And also an interesting Splunk Answers post about the use of realtime - https://community.splunk.com/t5/Random/Why-are-realtime-searches-disliked-in-the-Splunk-world/m-p/44...

 

🌟 Did this answer help you? If so, please consider:

  • Adding kudos to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...