<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to save search query in a file in Splunk Dashboard in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-save-search-query-in-a-file-in-Splunk-Dashboard/m-p/500384#M139319</link>
    <description>&lt;P&gt;You could create a scheduled report that runs once a day and configure it to output to a csv (using alert actions) and use a date token in the name of the csv so every day a new csv is generated. Then you would have the dashboard panels reference a lookup. you could have a dropdown selector that dynamically pulls a list of any csvs that have the naming convention used by the report by referencing the rest endpoint for lookups. &lt;/P&gt;

&lt;P&gt;The searches that do the inputlookup would use a token in place of the token name so whichever day's lookup the user selected from the dropdown would dynamically populate the dashboard.&lt;/P&gt;</description>
    <pubDate>Mon, 18 May 2020 14:55:52 GMT</pubDate>
    <dc:creator>acfecondo75</dc:creator>
    <dc:date>2020-05-18T14:55:52Z</dc:date>
    <item>
      <title>How to save search query in a file in Splunk Dashboard</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-save-search-query-in-a-file-in-Splunk-Dashboard/m-p/500383#M139318</link>
      <description>&lt;P&gt;Hi , &lt;/P&gt;

&lt;P&gt;I have a requirement where I want to save the search query after the query has run to a file. Basically i want to have a file with Query name and the query so that users can save and load back their queries in the Dashboard.&lt;/P&gt;

&lt;P&gt;Would like to know how can i save a query to a file using outputcsv in the Splunk Dashboard ? How do i get hold of that search query with resolved token values.&lt;/P&gt;

&lt;P&gt;Also is there a clean way that Splunk provides to save the dashboard query to a file?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 09:48:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-save-search-query-in-a-file-in-Splunk-Dashboard/m-p/500383#M139318</guid>
      <dc:creator>sambit_kabi</dc:creator>
      <dc:date>2020-05-18T09:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to save search query in a file in Splunk Dashboard</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-save-search-query-in-a-file-in-Splunk-Dashboard/m-p/500384#M139319</link>
      <description>&lt;P&gt;You could create a scheduled report that runs once a day and configure it to output to a csv (using alert actions) and use a date token in the name of the csv so every day a new csv is generated. Then you would have the dashboard panels reference a lookup. you could have a dropdown selector that dynamically pulls a list of any csvs that have the naming convention used by the report by referencing the rest endpoint for lookups. &lt;/P&gt;

&lt;P&gt;The searches that do the inputlookup would use a token in place of the token name so whichever day's lookup the user selected from the dropdown would dynamically populate the dashboard.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 14:55:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-save-search-query-in-a-file-in-Splunk-Dashboard/m-p/500384#M139319</guid>
      <dc:creator>acfecondo75</dc:creator>
      <dc:date>2020-05-18T14:55:52Z</dc:date>
    </item>
  </channel>
</rss>

