Splunk Enterprise Security

"notable events over time" panel is lagging behind the time

saurabh_tek11
Communicator

I want to understand the irregular behaviour of output displays for "notable events over time" panel in ES.
Right now its 4th july and its still showing data only till 3rd july. Whats wrong here..

What i have observed in past this panel does not keep up with time and shows data till some hours ago only.

The search SPL running this panel constituents a collection "es_notable_events" which is in KV store.
When i access this by - | inputlookup append=t es_notable_events, i see same old events which lags behind for some hours.

Now basically the issue is - this KV store lookup is not getting updated time to time causing the panel not to update and keep pace with time.

I want to understand why is this es_notable_events not getting updated and how does ES updates this ?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...