I have a search that runs in the web application interface (Splunk Enterprise). It returns results as and when log events are present within the search parameters (time window).
I execute the exact same search at the same time via the REST API using Postman, it completes (Job status="DONE") but with zero available events or any events at all.
Why might that happen? The search is copied and pasted from the web app to the API call in Postman. On occasion, it has worked but maybe one in a thousand calls will fetch results.