<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: savedsearch best practice in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/savedsearch-best-practice/m-p/431574#M5767</link>
    <description>&lt;P&gt;what is the exact requirement? what are you searching for across 'huge number of workstations"? how long does it takes to the search to complete?&lt;BR /&gt;
in any case, i'd recommend to schedule a report and also cap the exact time. example: run a search every night at 1:00 am, add to search: &lt;CODE&gt;earliest=-25h-15m@m latest=-1h-15m@m&lt;/CODE&gt; this will ensure you will not miss an event and even if your search takes 75 minutes to run. also, after i ran, you can use &lt;CODE&gt;|savedsearch&lt;/CODE&gt; or &lt;CODE&gt;|loadjob&lt;/CODE&gt; or just add it as a panel to a dashboard.&lt;/P&gt;</description>
    <pubDate>Mon, 22 Oct 2018 00:36:23 GMT</pubDate>
    <dc:creator>adonio</dc:creator>
    <dc:date>2018-10-22T00:36:23Z</dc:date>
    <item>
      <title>savedsearch best practice</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/savedsearch-best-practice/m-p/431573#M5766</link>
      <description>&lt;P&gt;hello&lt;/P&gt;

&lt;P&gt;i need to monitor events on a huge number of workstations &lt;BR /&gt;
i want to know the exact way to use saved search in order to execute the query at a planned date&lt;BR /&gt;
is it the good way to create a planned report, to copy data in a lookup and to call the data from a Dashboard&lt;BR /&gt;
or is it better to create a planned report and to call the report from the Dashboard with | savedserarch???&lt;BR /&gt;
Many thanks for your help&lt;/P&gt;</description>
      <pubDate>Sun, 21 Oct 2018 13:26:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/savedsearch-best-practice/m-p/431573#M5766</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2018-10-21T13:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: savedsearch best practice</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/savedsearch-best-practice/m-p/431574#M5767</link>
      <description>&lt;P&gt;what is the exact requirement? what are you searching for across 'huge number of workstations"? how long does it takes to the search to complete?&lt;BR /&gt;
in any case, i'd recommend to schedule a report and also cap the exact time. example: run a search every night at 1:00 am, add to search: &lt;CODE&gt;earliest=-25h-15m@m latest=-1h-15m@m&lt;/CODE&gt; this will ensure you will not miss an event and even if your search takes 75 minutes to run. also, after i ran, you can use &lt;CODE&gt;|savedsearch&lt;/CODE&gt; or &lt;CODE&gt;|loadjob&lt;/CODE&gt; or just add it as a panel to a dashboard.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 00:36:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/savedsearch-best-practice/m-p/431574#M5767</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-10-22T00:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: savedsearch best practice</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/savedsearch-best-practice/m-p/431575#M5768</link>
      <description>&lt;P&gt;I would suggest you to use datamodel if possible for optimizations &lt;/P&gt;</description>
      <pubDate>Sat, 27 Oct 2018 15:20:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/savedsearch-best-practice/m-p/431575#M5768</guid>
      <dc:creator>iamarkaprabha</dc:creator>
      <dc:date>2018-10-27T15:20:55Z</dc:date>
    </item>
  </channel>
</rss>

