Reporting

How do you access SII reports directly?

jackpal
Path Finder

I've saved a few charts in SII as reports so they could be embedded in another application. I've found no direct way of accessing these reports from SII. As a workaround, I've changed permissions to show in every app so they can be managed from the Search app. How does one access custom SII reports directly?

0 Karma
1 Solution

jackpal
Path Finder

Thanks, I did not explain that I am integrating SII into an existing Enterprise installation. I am able to do what I need to at this point. Thanks.

View solution in original post

jackpal
Path Finder

Thanks, I did not explain that I am integrating SII into an existing Enterprise installation. I am able to do what I need to at this point. Thanks.

mstjohn_splunk
Splunk Employee
Splunk Employee

Hey @jackpal,

Glad you figured out a solution to your problem. Would you mind writing an answer explaining how you solved it? If you could do that, and then approve it, it would serve as a guide for future splunkers with similar issues.

Thanks!!

0 Karma

jackpal
Path Finder

Well when the charts are displayed for a metric like user cpu time for example there are options to do a few things.

  • Create Alert
  • Open in Search
  • Save as Dashboard Panel
  • Save as Report
  • Clone this Panel
  • Export as PNG
  • Export as CSV

Based on the two options above (save as dashboard panel and save as report) I assumed I should be able to access them after creation and modify as needed. The normal dialog for permissions, scheduling, etc comes up after creation however unless I specify in permissions to share for all apps I am unable to access the report later to edit. That was basically my question.

So my workaround is just share with all apps when creating reports or panels or reports. This way if I need to edit the report I can access it in the search app and modify as needed. Like I mentioned earlier, I have an enterprise installation so I might probably have more abilities than somebody using the standalone version.

mstjohn_splunk
Splunk Employee
Splunk Employee

thanks @jackpal, our community loves ya for the explanation 🙂

0 Karma

abrown_splunk
Splunk Employee
Splunk Employee

Hi Jackpal - within the context of SII (the INSIGHT), the idea is that this is a stand-alone product. It is scoped to a specific use case and that's it. When you are talking about custom reports and dashboards, this is something you should do within Splunk Enterprise, using the Splunk APP for Infrastructure which supports a richer (and more complicated) experience. Does that make sense?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...