Splunk Search

Why is daily EPS get less?

Mien
New Member

Hi, 

May I know, why is daily EPS on specific date get less than usually? 

Is there any factor or cause to the less EPS count? 

Thank you. 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Mien ,

your question is just a little vague:

which days are you comparing?

which data source?

there could be many factors.

Ciao.

Giuseppe

0 Karma

Mien
New Member

Hi @gcusello 

For example, in a week, (average EPS). 18th Oct and 19th Oct got less than the actual. Meanwhile, on 15 Oct, 16 Oct, 17th Oct, 20th Oct and 21st Oct data looks normal. 

The data source, /opt/splunk/var/log/splunk/metrics.log

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Mien,

if the days in which you're receiving less data aren't the weekend, you should analyze if in that days there are some scheduled activities or a downtime of that systems.

In addition, you should analyze if this behaviour is all weeks or only in one.

then compare /opt/splunk/var/log/splunk/metrics.log file dimensions to understand if the issue is on Splunk or on the system.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...