Splunk新手疑问:设置interval值为60时每分钟生成2个随机事件是否为已知情况
Hey there! As someone who's spent plenty of time messing around with event generation in Splunk, I totally get why this would throw you off as a new user. The good news is this is a common, solvable scenario—let's break down the most likely reasons and fixes:
Common Causes
Accidental duplicate logic in your search: If you're using a search like
| makeresults | eval _raw=random() | append [| makeresults | eval _raw=random() | eval _time=_time-30], you're explicitly generating two events offset by 30 seconds. That would look like 2 events per minute even if you intended an interval of 60. Double-check your SPL forappend,join, or multiplemakeresultscalls that might be doubling up events.Incorrect cron schedule for scheduled searches: If you're running this as a scheduled search, make sure your cron expression isn't set to run every 30 seconds (like
*/30 * * * *). A search that fires twice per minute will generate one event each time, resulting in two total per minute.Data Generator plugin settings: If you're using the Splunk Add-on for Data Generator or a similar tool, check the configuration pane for an
event_countorevents_per_intervalparameter. Many of these tools default to generating multiple events per interval, so you'll want to set that value to 1 if you only want one event per minute.Initial startup quirk: Rarely, Splunk's event generators might fire twice when first launched to "catch up" if there was a slight delay in initializing the schedule. This should stop after the first minute, though—if it keeps happening, it's likely one of the above issues.
Quick Fixes to Verify
- Run your search manually once (not scheduled) and count the events returned. If you get 2 events immediately, your SPL is the culprit.
- Check your scheduled search's cron syntax—make sure it's set to
0 * * * *(run once per minute) instead of a more frequent interval. - For generator plugins, reset the configuration to default and then explicitly set
events per intervalto 1.
This is definitely a known scenario that pops up with new Splunk users, so don't worry—it's not a bug in the tool, just a small configuration tweak needed.
内容的提问来源于stack exchange,提问作者sisodo8186

