Knowledge Management

Run searches on app first install but not on upgrade

DanielFordWA
Contributor

I would like to create an app which when installed will do the following

  • Run a number searches against an already existing index during first install to output data to a summary index or a csv/lookup

  • Create a number of REST Modular inputs and run each one once when the app is first installed.

  • Setup a number of scheduled searches to run at a defined period.

Please can someone advise how I can trigger a search to run during an app first install but not on an upgrade?

Thanks,

Dan

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...