Splunk ITSI

Inaccurate Data over Time - Glass Table

logankinman99
Path Finder

I have Glass Tables that use KPIs refreshing their searches every 15 minutes to show data in real time. The data is accurate at first, and refreshes the searches fine.
After a few hours, however, the data starts to slip and show incorrect results. If I do an ad hoc search in a different tab, it shows totally different results than what the glass table is showing. This happens with all of my Glass Tables, as well, not just one.
I don't know if I set up something wrong, or if this is an issue other people are having. Please let me know. Thanks!

(Calculation: Calculating Average of __________ as aggregate over the last 15 minute(s) every 15 minute(s). Fill gaps in data with Null values and use a unknown threshold level for them.)

0 Karma

ivanreis
Builder

I would check the amount of skipped searches because it is possible that you are not getting them triggered on the schedule time and it can cause the gaps in your data.
Also check how long the reports does take to be completed using the job inspector
Run the report manually to check if you have the proper results, if so, it is potential you have issues with these skipped searches.
Are you working with summary index? If so, check if the reports are completed successfully or being triggered on the scheduled time.
Use the Management Console to check the report schedule
here is link to the document
https://docs.splunk.com/Documentation/Splunk/7.3.2/DMC/Scheduleractivity
If you are not able to identify the issue, open a case at Splunk support and upload the Splunk diag files for analysis.

logankinman99
Path Finder

Cool, thank you. I will look into these!

0 Karma

adonio
Ultra Champion

wild dart in the night, try to fill data gaps with last available value ... also try do it whenever you can ...

0 Karma

logankinman99
Path Finder

See that's what I was thinking too..It changed the results, but still didn't match the accurate searches

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...