Splunk Enterprise Security

"notable events over time" panel is lagging behind the time

saurabh_tek11
Communicator

I want to understand the irregular behaviour of output displays for "notable events over time" panel in ES.
Right now its 4th july and its still showing data only till 3rd july. Whats wrong here..

What i have observed in past this panel does not keep up with time and shows data till some hours ago only.

The search SPL running this panel constituents a collection "es_notable_events" which is in KV store.
When i access this by - | inputlookup append=t es_notable_events, i see same old events which lags behind for some hours.

Now basically the issue is - this KV store lookup is not getting updated time to time causing the panel not to update and keep pace with time.

I want to understand why is this es_notable_events not getting updated and how does ES updates this ?

0 Karma
Get Updates on the Splunk Community!

BSides Splunk 2022 - The Call for Papers is now Open!

TLDR; Main Site: https://bsidessplunk.com CFP Site: https://bsidessplunk.com/cfp CFP Opens: December 15th, ...

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...