Here I'm trying to extract the some data from the _raw content, ex : for now data in splunk: here the success run time will be _time2 _time=time2 , _raw=akjfkajdf4jlfadjf5453 _time=time1 , _raw=akjfkajdf6jlfadjf5457, So, when i again hit the splunk the data available in splunk like below _time=time3 , _raw=akjfkajdf4jlfadjf5453 _time=time4 , _raw=akjfkajdf6jlfadjf5457, _time=time2 , _raw=akjfkajdf4jlfadjf5454 _time=time1 , _raw=akjfkajdf6jlfadjf5455, so , using splunk api i need to get the data from last successful run to till now so my results should contain from time2 to now _time=time3 , _raw=akjfkajdf4jlfadjf5453 _time=time4 , _raw=akjfkajdf6jlfadjf5457, hope this will clarify, lemme know Need to integrate this logic in the spluk search query.
... View more