Splunk Search

Not getting the last week of data in graph when using the filter search Device_Type="mobile"

uagraw01
Motivator

 

uagraw01_0-1662527805116.png

In the above, I am comparing the last 15m data to the current week's 15m data. And I am getting good results.

 

uagraw01_1-1662527958772.png

 

But here in the same search when I am using the filter search Device_Type="mobile", I am not getting the last week of data in graph. Please help me out for this.

 

 

0 Karma

uagraw01
Motivator

@ITWhisperer  & @gcusello Yes, I can see no events for deviceType for last week. Those events appended to Splunk from 1st sep.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

So, the chart is providing the correct result. Splunk is not particular good at displaying things which don't exist. You can force it to by artificially adding events (with zero counts for example), but you have to tell Splunk which events you want adding.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @uagraw01,

if you haven't events that match the added condition, you have only to modify the search condition or accept these results.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @uagraw01,

there's only one answer: you haven't events that match the condition on week ago.

You can check this running your search only on the first time frame.

Ciao.

Giuseppe

ITWhisperer
SplunkTrust
SplunkTrust

This would seem to suggest that you have no events from last week for this device type - have you checked that there are actually events to be found?

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...