Getting Data In

What are the metrics.log fields avg_age and max_age?

myandow
Path Finder

Can someone point me to documentation that explains what the avg_age and max_age fields in the metrics logs are for? They do not appear in all of my metrics logs, but they are the last two fields when they do show up.

example:
05-09-2011 18:39:33.979 +0000 INFO Metrics - group=per_index_thruput, series="my_index", kbps=79.754883, eps=86.866667, kb=2392.646484, ev=2606, avg_age=420232.710668, max_age=420241

Tags (1)
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

avg_age is the average age of the events gathered in an index over the 30 second interval that this log entry covers. Similarly, max_age is the age of the oldest event gathered within that same 30 second interval.

Are you sure that the metrics lines collected prior to this were for the group 'per_index_thruput'? Not all of your metrics logs will contain all the same fields, as they gather and measure different things.

Entries like these would seem to indicate that very old data is being indexed, or there is some kind of a time stamp recognition issue that needs to be corrected.

I suspect that if you do an 'all time, real time' search on the index reporting this, you'll be able to make a determination as to which is the case.

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

avg_age is the average age of the events gathered in an index over the 30 second interval that this log entry covers. Similarly, max_age is the age of the oldest event gathered within that same 30 second interval.

Are you sure that the metrics lines collected prior to this were for the group 'per_index_thruput'? Not all of your metrics logs will contain all the same fields, as they gather and measure different things.

Entries like these would seem to indicate that very old data is being indexed, or there is some kind of a time stamp recognition issue that needs to be corrected.

I suspect that if you do an 'all time, real time' search on the index reporting this, you'll be able to make a determination as to which is the case.

Awittkower
Engager

For more information on metrics.log, check out this page in the docs: https://docs.splunk.com/Documentation/Splunk/7.1.2/Troubleshooting/Aboutmetricslog#Thruput_messages

0 Karma

kbecker
Communicator

Do you know what time value this is, seconds?

saravanan90
Contributor

Yes. The time value is in seconds.

0 Karma

rroberts
Splunk Employee
Splunk Employee

Useful! We need more on metrics.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...