I run a report every 24 hours, and I want to make the .csv results file available to multiple users afterwards. Can I configure the report to automatically save it to an alternate location rather than the default $SPLUNK_HOME/var/run/splunk/dispatch/<search_id>/results.csv.gz?
keeping the saved search artifact for longer in the $SPLUNK_HOME/var/run/splunk/dispatch dir, is done using the dispatch.ttl parameter in the saved search configuration. (It can get a bit complicated if there are actions that are triggered from the search).
You can also configure splunk to email those .csv results every day to anyone you want. It's in the saved search, alert actions, email and include results. Or you could trigger the shell script from the saved search-no need to issue command line search.