Knowledge Management

Run searches on app first install but not on upgrade

DanielFordWA
Contributor

I would like to create an app which when installed will do the following

  • Run a number searches against an already existing index during first install to output data to a summary index or a csv/lookup

  • Create a number of REST Modular inputs and run each one once when the app is first installed.

  • Setup a number of scheduled searches to run at a defined period.

Please can someone advise how I can trigger a search to run during an app first install but not on an upgrade?

Thanks,

Dan

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...