I'm new to Splunk and I find Splunk reports confusing.
In other SIEMS a report is the results of a previously ran query. However, it seems to be that reports are saved search queries without results of previous runs. So, when I click a report name it seems to be rerunning the query and now showing results of a previous run.
Are my assumptions & understand of reports correct?
It's most common for a report to run a query and display the results. It is possible, however, to create a report that displays the results of a previously-run saved search.