Splunk ITSI

Inaccurate Data over Time - Glass Table

logankinman99
Path Finder

I have Glass Tables that use KPIs refreshing their searches every 15 minutes to show data in real time. The data is accurate at first, and refreshes the searches fine.
After a few hours, however, the data starts to slip and show incorrect results. If I do an ad hoc search in a different tab, it shows totally different results than what the glass table is showing. This happens with all of my Glass Tables, as well, not just one.
I don't know if I set up something wrong, or if this is an issue other people are having. Please let me know. Thanks!

(Calculation: Calculating Average of __________ as aggregate over the last 15 minute(s) every 15 minute(s). Fill gaps in data with Null values and use a unknown threshold level for them.)

0 Karma

ivanreis
Builder

I would check the amount of skipped searches because it is possible that you are not getting them triggered on the schedule time and it can cause the gaps in your data.
Also check how long the reports does take to be completed using the job inspector
Run the report manually to check if you have the proper results, if so, it is potential you have issues with these skipped searches.
Are you working with summary index? If so, check if the reports are completed successfully or being triggered on the scheduled time.
Use the Management Console to check the report schedule
here is link to the document
https://docs.splunk.com/Documentation/Splunk/7.3.2/DMC/Scheduleractivity
If you are not able to identify the issue, open a case at Splunk support and upload the Splunk diag files for analysis.

logankinman99
Path Finder

Cool, thank you. I will look into these!

0 Karma

adonio
Ultra Champion

wild dart in the night, try to fill data gaps with last available value ... also try do it whenever you can ...

0 Karma

logankinman99
Path Finder

See that's what I was thinking too..It changed the results, but still didn't match the accurate searches

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...