Dashboards & Visualizations

How can I have one query for both a dashboard and an alert?

tb5821
Communicator

I want to have a query on my dashboard and also an alert for the same query but when it comes to updates. I don't want to have to update it in two places... what's the best way to accomplish this?

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi tb5821,
did you tried with a macro?
in other words: create a macro and use it both in dashboard and alert.
In this way you have only one point to manage.
Bye.
Giuseppe

View solution in original post

0 Karma

gowtham495
Path Finder

See if you can do this way :

  1. Create a Report with your search query and schedule it.
  2. Create a Dashboard and add a panel containing that Report.
  3. In Dashboard, Export >> Schedule PDF Delivery >> here you can edit settings like that of an alert (for ex: to, cc, cron, message, etc..)

This way, at the time of any updates, you can edit the Report alone. Other things will be automatically taken care of.

0 Karma

tb5821
Communicator

Looks like going this route doesn't allow for the 'scheduled report' to support Trigger Conditions or throttling of the report alert like it would with a 'regular' alert.

gcusello
SplunkTrust
SplunkTrust

Hi tb5821,
did you tried with a macro?
in other words: create a macro and use it both in dashboard and alert.
In this way you have only one point to manage.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...