Getting Data In

Can I modify Data from Splunk using Splunk API?

misteryuku
Communicator

Lets say if i do not search for the data using the splunk search then can i edit the data directly from the splunk server using the Splunk's REST api?

Tags (1)
0 Karma

Ayn
Legend

Edit as in change data that is already in Splunk's index? No. Once data is indexed, there is no (easy) way of altering it.

misteryuku
Communicator

Nothing i just want to know if there is such thing as updating the indexed data since i don't see any documentation on that on this Splunk website.

0 Karma

Ayn
Legend

Could you tell us a bit more about what you're trying to achieve?

0 Karma

Ayn
Legend

When you search in Splunk - regardless of which method you're using - you're getting your results from Splunk's index, yes.

0 Karma

misteryuku
Communicator

Normally when log file data is sent to splunk, splunk indexes the file data right? When you search for the result using Splunk's REST API, the result normally returns indexed data right? Am i right in both statements i made?

0 Karma

Ayn
Legend

OK. In that case the answer is no.

0 Karma

misteryuku
Communicator

Yes. That is what mean. Edit as in change data that is already in Splunk's index.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...