Splunk ITSI

Inaccurate Data over Time - Glass Table

logankinman99
Path Finder

I have Glass Tables that use KPIs refreshing their searches every 15 minutes to show data in real time. The data is accurate at first, and refreshes the searches fine.
After a few hours, however, the data starts to slip and show incorrect results. If I do an ad hoc search in a different tab, it shows totally different results than what the glass table is showing. This happens with all of my Glass Tables, as well, not just one.
I don't know if I set up something wrong, or if this is an issue other people are having. Please let me know. Thanks!

(Calculation: Calculating Average of __________ as aggregate over the last 15 minute(s) every 15 minute(s). Fill gaps in data with Null values and use a unknown threshold level for them.)

0 Karma

ivanreis
Builder

I would check the amount of skipped searches because it is possible that you are not getting them triggered on the schedule time and it can cause the gaps in your data.
Also check how long the reports does take to be completed using the job inspector
Run the report manually to check if you have the proper results, if so, it is potential you have issues with these skipped searches.
Are you working with summary index? If so, check if the reports are completed successfully or being triggered on the scheduled time.
Use the Management Console to check the report schedule
here is link to the document
https://docs.splunk.com/Documentation/Splunk/7.3.2/DMC/Scheduleractivity
If you are not able to identify the issue, open a case at Splunk support and upload the Splunk diag files for analysis.

logankinman99
Path Finder

Cool, thank you. I will look into these!

0 Karma

adonio
Ultra Champion

wild dart in the night, try to fill data gaps with last available value ... also try do it whenever you can ...

0 Karma

logankinman99
Path Finder

See that's what I was thinking too..It changed the results, but still didn't match the accurate searches

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...