Dashboards & Visualizations

How can I have one query for both a dashboard and an alert?

tb5821
Communicator

I want to have a query on my dashboard and also an alert for the same query but when it comes to updates. I don't want to have to update it in two places... what's the best way to accomplish this?

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi tb5821,
did you tried with a macro?
in other words: create a macro and use it both in dashboard and alert.
In this way you have only one point to manage.
Bye.
Giuseppe

View solution in original post

0 Karma

gowtham495
Path Finder

See if you can do this way :

  1. Create a Report with your search query and schedule it.
  2. Create a Dashboard and add a panel containing that Report.
  3. In Dashboard, Export >> Schedule PDF Delivery >> here you can edit settings like that of an alert (for ex: to, cc, cron, message, etc..)

This way, at the time of any updates, you can edit the Report alone. Other things will be automatically taken care of.

0 Karma

tb5821
Communicator

Looks like going this route doesn't allow for the 'scheduled report' to support Trigger Conditions or throttling of the report alert like it would with a 'regular' alert.

gcusello
SplunkTrust
SplunkTrust

Hi tb5821,
did you tried with a macro?
in other words: create a macro and use it both in dashboard and alert.
In this way you have only one point to manage.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...