Getting Data In

How to optimize script in Splunk

nguyenhuyhoang0
New Member

Hi folks,
Now, I want to poll API with the result shown below.
The Splunk poll API interval three times respectively, In new polling API, it may have duplicate alert_id with the previous one. I want to save up to date alert_id instead in order to guarantee the Splunk output always store newly information.
Anyone has ideas and can share?
alt text

0 Karma

jnudell_2
Builder

You're going to have to provide a lot more detail that what you've described so far.

What is the API?
Are you creating a modular input in a custom app?
Are you using Application Builder?
Are you look to create a state table (not what Splunk is meant to do really, but has workarounds like lookups)?
Can you describe the programmatic workflow differently to provide more context and sample values?

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...