However, when I look in Splunk, I do not see any events being updated. The data is being indexed, and I can search for the data with 'index = netapps'. But I don't see any updates like below. What gives?
I'm glad you figured out an answer to your query. Would you please describe what you did to solve it in an answer below? Then, close the question by approving your solution. That way, others will be able to learn from your experience.