Reporting

Do Reports contain results of past searches or are they only a reference to a saved search query?

koocies
Path Finder

I'm new to Splunk and I find Splunk reports confusing.

In other SIEMS a report is the results of a previously ran query. However, it seems to be that reports are saved search queries without results of previous runs. So, when I click a report name it seems to be rerunning the query and now showing results of a previous run.

Are my assumptions & understand of reports correct?

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's most common for a report to run a query and display the results.  It is possible, however, to create a report that displays the results of a previously-run saved search.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...