Getting Data In

Is it possible to have scheduled saved search using summary indexing and dynamic token depending on user query?

splunkreal
Motivator

Hello,
one user wants to convert dashboard with token to summary indexing dashboard.
We are using | sistats or similar, scheduling data collection each minute or other frequency.

However user has token input to filter later dynamically search results.

Is it possible to have scheduled saved search using summary indexing and dynamic token depending on user query?

May I remove the filter and grab all results then filter in the final summary indexing dashboard?

Thanks for your help.

* If this helps, please upvote or accept solution if it solved *
Labels (1)
0 Karma
Get Updates on the Splunk Community!

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...