Splunk Enterprise Security

"notable events over time" panel is lagging behind the time


I want to understand the irregular behaviour of output displays for "notable events over time" panel in ES.
Right now its 4th july and its still showing data only till 3rd july. Whats wrong here..

What i have observed in past this panel does not keep up with time and shows data till some hours ago only.

The search SPL running this panel constituents a collection "es_notable_events" which is in KV store.
When i access this by - | inputlookup append=t es_notable_events, i see same old events which lags behind for some hours.

Now basically the issue is - this KV store lookup is not getting updated time to time causing the panel not to update and keep pace with time.

I want to understand why is this es_notable_events not getting updated and how does ES updates this ?

0 Karma
Get Updates on the Splunk Community!

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...

Want a chance to win $500 to the Splunk shop? Take our IT Incident Management Survey!

  Top Trends & Best Practices in Incident ManagementSplunk is partnering up with Constellation Research to ...