Splunk Search

Why is daily EPS get less?

Mien
New Member

Hi, 

May I know, why is daily EPS on specific date get less than usually? 

Is there any factor or cause to the less EPS count? 

Thank you. 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Mien ,

your question is just a little vague:

which days are you comparing?

which data source?

there could be many factors.

Ciao.

Giuseppe

0 Karma

Mien
New Member

Hi @gcusello 

For example, in a week, (average EPS). 18th Oct and 19th Oct got less than the actual. Meanwhile, on 15 Oct, 16 Oct, 17th Oct, 20th Oct and 21st Oct data looks normal. 

The data source, /opt/splunk/var/log/splunk/metrics.log

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Mien,

if the days in which you're receiving less data aren't the weekend, you should analyze if in that days there are some scheduled activities or a downtime of that systems.

In addition, you should analyze if this behaviour is all weeks or only in one.

then compare /opt/splunk/var/log/splunk/metrics.log file dimensions to understand if the issue is on Splunk or on the system.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...