<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Report on a saved search? in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Report-on-a-saved-search/m-p/49903#M1055</link>
    <description>&lt;P&gt;Add " | stats count" to the end of your search to show the count of events, in your example "3".&lt;/P&gt;</description>
    <pubDate>Tue, 14 Sep 2010 23:24:06 GMT</pubDate>
    <dc:creator>hulahoop</dc:creator>
    <dc:date>2010-09-14T23:24:06Z</dc:date>
    <item>
      <title>Report on a saved search?</title>
      <link>https://community.splunk.com/t5/Reporting/Report-on-a-saved-search/m-p/49902#M1054</link>
      <description>&lt;P&gt;Hello,
After playing with Splunk, I was able to create a save search that would email us if an IP address has more than 500 failed attempts on our firewalls. The search runs every 60 mins.&lt;/P&gt;

&lt;P&gt;Next, I would like to create a weekly summary report. i.e if 1.1.1.1 triggers an alert 3 separate times in the previous week, then the report will show 3. I tried creating a report on the saved search and having it run once a week, but that method displayed how many total fail attempts for the week, not the count. I’m not sure how to create a report on a save search or if I need to write a more complex search query. Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2010 23:05:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Report-on-a-saved-search/m-p/49902#M1054</guid>
      <dc:creator>jnguy</dc:creator>
      <dc:date>2010-09-14T23:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: Report on a saved search?</title>
      <link>https://community.splunk.com/t5/Reporting/Report-on-a-saved-search/m-p/49903#M1055</link>
      <description>&lt;P&gt;Add " | stats count" to the end of your search to show the count of events, in your example "3".&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2010 23:24:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Report-on-a-saved-search/m-p/49903#M1055</guid>
      <dc:creator>hulahoop</dc:creator>
      <dc:date>2010-09-14T23:24:06Z</dc:date>
    </item>
  </channel>
</rss>

