Reporting

Is it possible to sync updates to index?

jimams
New Member

The scenario:

  1. via REST API, a scheduled search runs and updates an index, it adds values: Field1='A', Field2='1'; the splunk job is finished and finalized.
  2. via the REST API, the same scheduled search runs again and updates an index, it adds values: Field1='B', Field2='2'; the splunk job again is finished and finalized.
  3. another scheduled search runs and checks the content of the index ... but sometimes it only sees values Field1='A', Field2='1' ... it doesn't see the values submitted to the index the second time. When I run the same scheduled search a bit later, I already can see the values Field1='B', Field2='2'.

So, maybe it's a part of an optimization, but I would like to make sure in this particular case that when a job is done, the data is always available for another search after that.

Is there a way as how to achieve that? Thanks for any help!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...