I have a splunk dashboard in which I have to upload a lookup file to all the dashboard panels queries
And the lookup I upload is a result of a splunk query.
Now, Instead of running the query regularly and uploading the lookup file to the dashboard manually are there any other alternative ways in splunk that I can avoid the manual process and make it an auto upload everyday?
Hi pavanae,
did you tried to use a summary?
you can use your splunk query to populate a summary and then use it for your searches.
In other words
my search
| table field1 field2 field3 ...
| collect index=my_summary_index
Then use to search
index=my_summary_index
| table field1 field2 field3 ...
Bye.
Giuseppe