Is there a 20 minute delay in event logs?
At 13:54, the log entry at 13:30 appeared. Even after refresh, as well as clicking Network Wide -> Event log, several times in between.
I checked in on the Event log at 14:06 and nothing. Shortly thereafter;
I'm not good at math but
- at 13:54 you cannot see the log of 14:00
- at 14:06 you can see the log of 14:00
it's natural.
If you have another network, you can check the delay
@natuan wrote:I'm not good at math but
- at 13:54 you cannot see the log of 14:00
- at 14:06 you can see the log of 14:00
it's natural.
If you have another network, you can check the delay
No. I could not see the log entry at 13:30, untill 13:54.
The entry at 14:00, did not appear until at 14:07.
Another thing I'm curioust about is that I have difficulty in believing that I'm getting the same two "Source IP and/or VLAN mismatch" events every 30 minutes, precisely on the second, for the last month.
Has anyone gotten an answer to this? My meraki logs show about a 10 minute delay.
There seems to be a fair amount of alarm suppression happening (event log presentation)
Noticed that something like blocked malware is about an hour lead time until it shows in logs and sends alerts.
15 minutes (approx) for cellular up/down
Down is 5-10 minutes
Failover approx 5mins
It could mean that these alerts have different values, or that the boxes when getting lots of event log hits, place notification on a lower priority and that accounts for the delays in alerts being sent and logs being populated
Same issue here. Got on at 17:50. Kept refreshing constantly, no log messages after 17:44. Finally at 18:01 2 1/2 pages of new entries showed up. Do they only update every 15 minutes? Makes troubleshooting VPNs and such quite difficult.
I noticed the same issue. It took at least 20 minutes before the logs where showing in the "Event log" search. I don't think it has been this slow in the past.