Splunk Search

Phantom poling data from splunk

ansusabu
Communicator

I have a playbook that writes data to an index a. And I am polling events which are closed , ie, `notable|search status="x"` and data of this event from index 'a' as well. ie, I am using a nested query to get the data. But when I close one of the latest events, that event gets polled immediately, and after that, if I close an event older than that it is not getting polled. Have anyone faced such issue?

0 Karma
Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...