In this article:
Data from the Splunk integration is two to three days old.
The delay is expected. When our history events endpoint is called, it may return data from the past two or three.
Note: The integration does not omit or miss delayed data and eventually posts it.