Getting Data In

Is it possible to have scheduled saved search using summary indexing and dynamic token depending on user query?

splunkreal
Motivator

Hello,
one user wants to convert dashboard with token to summary indexing dashboard.
We are using | sistats or similar, scheduling data collection each minute or other frequency.

However user has token input to filter later dynamically search results.

Is it possible to have scheduled saved search using summary indexing and dynamic token depending on user query?

May I remove the filter and grab all results then filter in the final summary indexing dashboard?

Thanks for your help.

* If this helps, please upvote or accept solution if it solved *
Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...