Dashboards & Visualizations

How can I have one query for both a dashboard and an alert?

tb5821
Communicator

I want to have a query on my dashboard and also an alert for the same query but when it comes to updates. I don't want to have to update it in two places... what's the best way to accomplish this?

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi tb5821,
did you tried with a macro?
in other words: create a macro and use it both in dashboard and alert.
In this way you have only one point to manage.
Bye.
Giuseppe

View solution in original post

0 Karma

gowtham495
Path Finder

See if you can do this way :

  1. Create a Report with your search query and schedule it.
  2. Create a Dashboard and add a panel containing that Report.
  3. In Dashboard, Export >> Schedule PDF Delivery >> here you can edit settings like that of an alert (for ex: to, cc, cron, message, etc..)

This way, at the time of any updates, you can edit the Report alone. Other things will be automatically taken care of.

0 Karma

tb5821
Communicator

Looks like going this route doesn't allow for the 'scheduled report' to support Trigger Conditions or throttling of the report alert like it would with a 'regular' alert.

gcusello
SplunkTrust
SplunkTrust

Hi tb5821,
did you tried with a macro?
in other words: create a macro and use it both in dashboard and alert.
In this way you have only one point to manage.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...