About metrics in the Data Monitoring dashboard
Metrics displayed in the data monitoring dashboard are based on results from scheduled searches. The Data Monitoring dashboard starts running these searches as soon as the Data Monitoring app is installed. These scheduled searches are run on License Usage logs from _internal index (index=_internal source= license_usage.log).
Searches are performed in five minute intervals. For example, five minutes after installation, your dashboard will show five minutes of data, ten minutes of data in ten minutes, etc. This means that Splunk may temporarily display empty or incomplete results as the metrics build up over time. The calculated metrics are stored in a metrics index called "gdi_summary_metrics" which is created using indexes.conf.
Scheduled searches start running when the app is installed and the app does not run searches for historical time periods, therefore the app only provides visibility or metrics from the installation time onwards.
Terms | Data squashing impact on data monitoring |
This documentation applies to the following versions of Splunk® Enterprise: DataMonitoringAppPreview
Feedback submitted, thanks!