Getting Data In

What are the metrics.log fields avg_age and max_age?

myandow
Path Finder

Can someone point me to documentation that explains what the avg_age and max_age fields in the metrics logs are for? They do not appear in all of my metrics logs, but they are the last two fields when they do show up.

example:
05-09-2011 18:39:33.979 +0000 INFO Metrics - group=per_index_thruput, series="my_index", kbps=79.754883, eps=86.866667, kb=2392.646484, ev=2606, avg_age=420232.710668, max_age=420241

Tags (1)
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

avg_age is the average age of the events gathered in an index over the 30 second interval that this log entry covers. Similarly, max_age is the age of the oldest event gathered within that same 30 second interval.

Are you sure that the metrics lines collected prior to this were for the group 'per_index_thruput'? Not all of your metrics logs will contain all the same fields, as they gather and measure different things.

Entries like these would seem to indicate that very old data is being indexed, or there is some kind of a time stamp recognition issue that needs to be corrected.

I suspect that if you do an 'all time, real time' search on the index reporting this, you'll be able to make a determination as to which is the case.

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

avg_age is the average age of the events gathered in an index over the 30 second interval that this log entry covers. Similarly, max_age is the age of the oldest event gathered within that same 30 second interval.

Are you sure that the metrics lines collected prior to this were for the group 'per_index_thruput'? Not all of your metrics logs will contain all the same fields, as they gather and measure different things.

Entries like these would seem to indicate that very old data is being indexed, or there is some kind of a time stamp recognition issue that needs to be corrected.

I suspect that if you do an 'all time, real time' search on the index reporting this, you'll be able to make a determination as to which is the case.

Awittkower
Engager

For more information on metrics.log, check out this page in the docs: https://docs.splunk.com/Documentation/Splunk/7.1.2/Troubleshooting/Aboutmetricslog#Thruput_messages

0 Karma

kbecker
Communicator

Do you know what time value this is, seconds?

saravanan90
Contributor

Yes. The time value is in seconds.

0 Karma

rroberts
Splunk Employee
Splunk Employee

Useful! We need more on metrics.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...