<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Saving Search Results in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Saving-Search-Results/m-p/80645#M16642</link>
    <description>&lt;P&gt;When you saved did you hit &lt;B&gt;save results&lt;/B&gt; or &lt;B&gt;save search&lt;/B&gt;? It sounds like you might have done the latter which will re-populate the data every time as you are saving the search criteria instead of the results. If you save the search results even 2 million hits shouldn't take that long to come back. These options are under the Actions dropdown.&lt;/P&gt;

&lt;P&gt;Once the results are saved you can find them in the Jobs section.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Apr 2011 22:40:00 GMT</pubDate>
    <dc:creator>I-Man</dc:creator>
    <dc:date>2011-04-13T22:40:00Z</dc:date>
    <item>
      <title>Saving Search Results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Saving-Search-Results/m-p/80644#M16641</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I am very new to Splunk. I have got it up and running on a Linux Box and analyzing some IIS logs and everything works perfect.&lt;/P&gt;

&lt;P&gt;But my question is I saved a search with a date range of March 1 to March 31. These logs have about 2 million hits or events. It takes a long time to build. &lt;/P&gt;

&lt;P&gt;Is there not a way once the events are scanned not to re-scan them? Just that it takes like 15 minutes every time I open the search.&lt;/P&gt;

&lt;P&gt;Thanks &lt;/P&gt;

&lt;P&gt;Mike &lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2011 22:26:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Saving-Search-Results/m-p/80644#M16641</guid>
      <dc:creator>mdumka</dc:creator>
      <dc:date>2011-04-13T22:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: Saving Search Results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Saving-Search-Results/m-p/80645#M16642</link>
      <description>&lt;P&gt;When you saved did you hit &lt;B&gt;save results&lt;/B&gt; or &lt;B&gt;save search&lt;/B&gt;? It sounds like you might have done the latter which will re-populate the data every time as you are saving the search criteria instead of the results. If you save the search results even 2 million hits shouldn't take that long to come back. These options are under the Actions dropdown.&lt;/P&gt;

&lt;P&gt;Once the results are saved you can find them in the Jobs section.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2011 22:40:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Saving-Search-Results/m-p/80645#M16642</guid>
      <dc:creator>I-Man</dc:creator>
      <dc:date>2011-04-13T22:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: Saving Search Results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Saving-Search-Results/m-p/80646#M16643</link>
      <description>&lt;P&gt;Perfect ... Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2011 04:25:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Saving-Search-Results/m-p/80646#M16643</guid>
      <dc:creator>mdumka</dc:creator>
      <dc:date>2011-04-14T04:25:32Z</dc:date>
    </item>
  </channel>
</rss>

