Reporting

Do Reports contain results of past searches or are they only a reference to a saved search query?

koocies
Path Finder

I'm new to Splunk and I find Splunk reports confusing.

In other SIEMS a report is the results of a previously ran query. However, it seems to be that reports are saved search queries without results of previous runs. So, when I click a report name it seems to be rerunning the query and now showing results of a previous run.

Are my assumptions & understand of reports correct?

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's most common for a report to run a query and display the results.  It is possible, however, to create a report that displays the results of a previously-run saved search.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...