Dashboards & Visualizations

What are the differences and pros/cons between inline search and saved search?

maxdranitski
Explorer

Hi there,

I created some Pivots and Dashboards...
All my graphics are presented as Inline Search on the Dashboards at the current time.

Question is: Should I converted it to Report type, and what is the reason to do it?

1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Reports are saved searches. Common reasons to convert is reusability in other dashboards or as a standalone report/alert, scheduling, acceleration, and general organization of your knowledge objects.
Common reasons to not convert - less pollution of your app's namespace from reports only used on one dashboard, speed of changes during dashboard development, and general laziness.

View solution in original post

somesoni2
Revered Legend

martin_mueller
SplunkTrust
SplunkTrust

Reports are saved searches. Common reasons to convert is reusability in other dashboards or as a standalone report/alert, scheduling, acceleration, and general organization of your knowledge objects.
Common reasons to not convert - less pollution of your app's namespace from reports only used on one dashboard, speed of changes during dashboard development, and general laziness.

maxdranitski
Explorer

Thank you Martin for the answer!

0 Karma

nawneel
Communicator

@martin_mueller Hey just a clarification , if i have 1 saved search which i have incorporated at 5 dashboards , will this search run 5 times or just a single run will populate all dashbaord. Thanks in advance

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...