Getting Data In

How to optimize script in Splunk

nguyenhuyhoang0
New Member

Hi folks,
Now, I want to poll API with the result shown below.
The Splunk poll API interval three times respectively, In new polling API, it may have duplicate alert_id with the previous one. I want to save up to date alert_id instead in order to guarantee the Splunk output always store newly information.
Anyone has ideas and can share?
alt text

0 Karma

jnudell_2
Builder

You're going to have to provide a lot more detail that what you've described so far.

What is the API?
Are you creating a modular input in a custom app?
Are you using Application Builder?
Are you look to create a state table (not what Splunk is meant to do really, but has workarounds like lookups)?
Can you describe the programmatic workflow differently to provide more context and sample values?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...