Splunk Enterprise Security

"notable events over time" panel is lagging behind the time

saurabh_tek11
Communicator

I want to understand the irregular behaviour of output displays for "notable events over time" panel in ES.
Right now its 4th july and its still showing data only till 3rd july. Whats wrong here..

What i have observed in past this panel does not keep up with time and shows data till some hours ago only.

The search SPL running this panel constituents a collection "es_notable_events" which is in KV store.
When i access this by - | inputlookup append=t es_notable_events, i see same old events which lags behind for some hours.

Now basically the issue is - this KV store lookup is not getting updated time to time causing the panel not to update and keep pace with time.

I want to understand why is this es_notable_events not getting updated and how does ES updates this ?

0 Karma
Get Updates on the Splunk Community!

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...

DevSecOps: Why You Should Care and How To Get Started

 WATCH NOW In this Tech Talk we will talk about what people mean by DevSecOps and deep dive into the different ...