Splunk Search

Can I resolve this splunk dashboard index auto refresh / resync issue?

pp3295
Explorer

hi all,

we  are creating one dashboard having two tables , in that we have set different folder locations for monitoring. 

BAU table 1 query = source="F:\\Logshipping\\Export\\BAU\\*" host="FinIQDB-DR" index="index_bau" EP_ER_QuoteRequestId= * EP_ER_QuoteRequestId != "EP_ER_QuoteRequestId"| dedup EP_ER_QuoteRequestId| table EP_ER_QuoteRequestId, orderStatus,EP_ExternalOrderId,ER_Created_At,ER_Created_By,EP_Order_Requested_At,EP_Order_Response_At,ER_Type,EP_ordertype,ER_UnderlyingCode,ER_LimitPrice1,ER_LimitPrice2,ER_LimitPrice3 ,source

 

DR table 2 query = source="F:\\Logshipping\\Export\\DR\\*" host="FinIQDB-DR" index="index_dr" EP_ER_QuoteRequestId= * EP_ER_QuoteRequestId != "EP_ER_QuoteRequestId"| dedup EP_ER_QuoteRequestId| table EP_ER_QuoteRequestId, orderStatus,EP_ExternalOrderId,ER_Created_At,ER_Created_By,EP_Order_Requested_At,EP_Order_Response_At,ER_Type,EP_ordertype,ER_UnderlyingCode,ER_LimitPrice1,ER_LimitPrice2,ER_LimitPrice3 ,source

** Screenshot

2023_01_11_splunk.png

 

1. We are getting updated records  in BAU table ,whenever file is updated into folder 

2. We are not able to get updated records in DR table , when file is updated, in that case we have to 

delete an index and re-create it .  then new records are populated in the grid.

thanks.

 

 

 

 

 

 

 

 

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What is the difference between the configuration for the BAU file monitoring and the DR file monitoring?

Are the new events available from the search and reporting app, just not in the dashboard table?

Do you get the new events if you refresh the browser window?

0 Karma

pp3295
Explorer

thanks for your reply.

What is the difference between the configuration for the BAU file monitoring and the DR file monitoring?

pp= actually we have added two local inputs under files and directories.  as folder continuous monitor and created two different index as index_bau, index_dr for them and assigned to them.

Are the new events available from the search and reporting app, just not in the dashboard table?

pp= in search we are also not getting new events, for populate new events we have to delete existing index and re-create , then search and dashboard shows new events.

Do you get the new events if you refresh the browser window?

pp= after browser refresh , index not refreshed, we are using splunk on windows  10

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
Can you post a real inputs.conf files which are used to collect those events. Also check on client side that those are correct ones with splunk btool.
Also are there any props.conf and transforms.conf used on your environment?
Is this one node installation or have you separate nodes where you have installed UF's to collect those events?
r. Ismo
0 Karma

pp3295
Explorer

Not using any forwarder, just single Splunk server installation to monitor Local file.

pp3295_0-1673500347524.png

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Are those local drives or network shares mapped to local drive letters?
Which user you are using to run splunk?
0 Karma

pp3295
Explorer

thanks for your reply.

Our F:\\Logshipping\\Export\\BAU\ or F:\\Logshipping\\Export\\BAU\ is local shared folder .

we are copying files from other vm to this location and we are using admin user

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...