Reporting

Is it possible to sync updates to index?

jimams
New Member

The scenario:

  1. via REST API, a scheduled search runs and updates an index, it adds values: Field1='A', Field2='1'; the splunk job is finished and finalized.
  2. via the REST API, the same scheduled search runs again and updates an index, it adds values: Field1='B', Field2='2'; the splunk job again is finished and finalized.
  3. another scheduled search runs and checks the content of the index ... but sometimes it only sees values Field1='A', Field2='1' ... it doesn't see the values submitted to the index the second time. When I run the same scheduled search a bit later, I already can see the values Field1='B', Field2='2'.

So, maybe it's a part of an optimization, but I would like to make sure in this particular case that when a job is done, the data is always available for another search after that.

Is there a way as how to achieve that? Thanks for any help!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...