Splunk Enterprise Security

Why is notable Macro not returning results in realtime searches via search API?

ismailawan
Engager

We use the splunk search endpoint to get notable events using the search endpoint
services/search/jobs

search=search `notable`
earliest_time=(currentTime - 2min)
latest_time=(currentTime)
adhoc_search_level=smart

When search is completed
services/search/jobs/<sid>
dispatchState = DONE

We get results
services/search/jobs/<sid>/results

We don't get all the results.

But when we make the same search with same time ranges around 10 to 15 mins later, we get the results which we missed in the realtime search.

Why do we get the issue and how do we resolve the issue ?

Labels (1)
Tags (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's possible the data takes more than 2 minutes to be indexed.  Try changing earliest_time to -4 minutes

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...