Getting Data In

How to optimize script in Splunk

nguyenhuyhoang0
New Member

Hi folks,
Now, I want to poll API with the result shown below.
The Splunk poll API interval three times respectively, In new polling API, it may have duplicate alert_id with the previous one. I want to save up to date alert_id instead in order to guarantee the Splunk output always store newly information.
Anyone has ideas and can share?
alt text

0 Karma

jnudell_2
Builder

You're going to have to provide a lot more detail that what you've described so far.

What is the API?
Are you creating a modular input in a custom app?
Are you using Application Builder?
Are you look to create a state table (not what Splunk is meant to do really, but has workarounds like lookups)?
Can you describe the programmatic workflow differently to provide more context and sample values?

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...