Getting Data In

Is it possible to have scheduled saved search using summary indexing and dynamic token depending on user query?

splunkreal
Motivator

Hello,
one user wants to convert dashboard with token to summary indexing dashboard.
We are using | sistats or similar, scheduling data collection each minute or other frequency.

However user has token input to filter later dynamically search results.

Is it possible to have scheduled saved search using summary indexing and dynamic token depending on user query?

May I remove the filter and grab all results then filter in the final summary indexing dashboard?

Thanks for your help.

* If this helps, please upvote or accept solution if it solved *
Labels (1)
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...