Splunk IT Service Intelligence

Inaccurate Data over Time - Glass Table

Path Finder

I have Glass Tables that use KPIs refreshing their searches every 15 minutes to show data in real time. The data is accurate at first, and refreshes the searches fine.
After a few hours, however, the data starts to slip and show incorrect results. If I do an ad hoc search in a different tab, it shows totally different results than what the glass table is showing. This happens with all of my Glass Tables, as well, not just one.
I don't know if I set up something wrong, or if this is an issue other people are having. Please let me know. Thanks!

(Calculation: Calculating Average of __________ as aggregate over the last 15 minute(s) every 15 minute(s). Fill gaps in data with Null values and use a unknown threshold level for them.)

0 Karma


I would check the amount of skipped searches because it is possible that you are not getting them triggered on the schedule time and it can cause the gaps in your data.
Also check how long the reports does take to be completed using the job inspector
Run the report manually to check if you have the proper results, if so, it is potential you have issues with these skipped searches.
Are you working with summary index? If so, check if the reports are completed successfully or being triggered on the scheduled time.
Use the Management Console to check the report schedule
here is link to the document
If you are not able to identify the issue, open a case at Splunk support and upload the Splunk diag files for analysis.

Path Finder

Cool, thank you. I will look into these!

0 Karma

Ultra Champion

wild dart in the night, try to fill data gaps with last available value ... also try do it whenever you can ...

0 Karma

Path Finder

See that's what I was thinking too..It changed the results, but still didn't match the accurate searches

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!


Or Learn More in Our Blog >>