Splunk Search

Realtime search question

ericrobinson
Path Finder

I have splunk forwarders configured on 3 machines going to a splunk receiver. I have a request to create a real-time dashboard.

My question is why I can only see events from one of the forwarders when I do a 30 second window real-time search. Is there something configured in the forwarder that enables/disables rt search?

Tags (1)
0 Karma

Stephen_Sorkin
Splunk Employee
Splunk Employee

This is most likely caused by time skew on the two forwarders that are not being reported. The time window is the most recent 30s relative to the clock on the node that you're doing the search from. To confirm this, you can run a search over all-time real-time like:

index=* | eval lag = _time-_indextime | stats min(lag) max(lag) by host
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...