Splunk Search

Phantom poling data from splunk

ansusabu
Communicator

I have a playbook that writes data to an index a. And I am polling events which are closed , ie, `notable|search status="x"` and data of this event from index 'a' as well. ie, I am using a nested query to get the data. But when I close one of the latest events, that event gets polled immediately, and after that, if I close an event older than that it is not getting polled. Have anyone faced such issue?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...