Is there anyway to run a series of queries - anywhere from 10 to 60 - and have a report generated?
I'm being discouraged from using the API (and I'm not an administrator) to run queries, but I'm struggling to figure out another way that I can automate running the queries that I'm creating based on alerts from another application.
Hi @microserfs,
the only way to have a dyniamic list of savedsearches is REST API.
If you aren't an administrator, you could create the search and give to an administrator.
Ciao.
Giuseppe
Hi @microserfs,
the only way to have a dyniamic list of savedsearches is REST API.
If you aren't an administrator, you could create the search and give to an administrator.
Ciao.
Giuseppe
Do you mean you want to run a splunk search? Can you not just create a search, save it as a report and schedule it to run when you want to.
Unfortunately there are two many changing variables that I have to pull from another source