<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic All time (real-time) search through the API in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/All-time-real-time-search-through-the-API/m-p/176822#M35489</link>
    <description>&lt;P&gt;I'm trying to do a real-time search using the REST API- I've got a bit of a delay indexing, and I want events as they are indexed, even if they are old.  In the UI, I can specify an 'All-time (real-time)' search and get that behavior, but I can't figure out how to specify that behavior using the API.  If I use earliest_time = 'rt' I seem to miss events, if I use a window like earliest_time = rt-1h I get a lot of events with preview=true and it appears they are duplicated.  What is the proper earliest_time value to use for this type of search?&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 15:28:23 GMT</pubDate>
    <dc:creator>zenmoto</dc:creator>
    <dc:date>2020-09-28T15:28:23Z</dc:date>
    <item>
      <title>All time (real-time) search through the API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/All-time-real-time-search-through-the-API/m-p/176822#M35489</link>
      <description>&lt;P&gt;I'm trying to do a real-time search using the REST API- I've got a bit of a delay indexing, and I want events as they are indexed, even if they are old.  In the UI, I can specify an 'All-time (real-time)' search and get that behavior, but I can't figure out how to specify that behavior using the API.  If I use earliest_time = 'rt' I seem to miss events, if I use a window like earliest_time = rt-1h I get a lot of events with preview=true and it appears they are duplicated.  What is the proper earliest_time value to use for this type of search?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:28:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/All-time-real-time-search-through-the-API/m-p/176822#M35489</guid>
      <dc:creator>zenmoto</dc:creator>
      <dc:date>2020-09-28T15:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: All time (real-time) search through the API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/All-time-real-time-search-through-the-API/m-p/176823#M35490</link>
      <description>&lt;P&gt;I think I figured this out myself- though I'd dug into the _internal logs, inspected searches, combed through documentation and been unable to find it I just happened to be looking at my URL bar as I did an 'All time (real-time)' search in the GUI and saw the time parameters- '&amp;amp;earliest=rt&amp;amp;latest=rt'.  So it looks like having both earliest_time and latest_time set to 'rt' seems to be the answer- I just need to chase down why it is working in the GUI but isn't working via the API.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2013 19:49:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/All-time-real-time-search-through-the-API/m-p/176823#M35490</guid>
      <dc:creator>zenmoto</dc:creator>
      <dc:date>2013-12-12T19:49:15Z</dc:date>
    </item>
  </channel>
</rss>

