Reporting

Is it possible to use a scheduled search within a dataset?

spammenot66
Contributor

I like splunk's pivot table capabilities and am wondering if its possible to use a scheduled search within a dataset. You may ask, why not drop in the full query from the scheduled search into the datamodel then accelerate it. I've had issues with the accelerated data model consuming too much resource in the past and am trying to avoid it by using scheduled search to ensure it runs specific time at specific intervals. In going this route, I am missing out on the pivot UI

0 Karma

woodcock
Esteemed Legend

A dataset can be a simple lookup file so all you need to do is setup a scheduled search and use | outputlookup or the built-in alerting function to save results to a lookup file. Put in whatever schedule suits you and update the lookup file that you have also setup as a dataset.

0 Karma

DalJeanis
Legend

Hmmm. Is your scheduled search producing a reasonably small output, relative to the data being searched?

If so, then consider using your scheduled search to load a summary index, then basing your datamodel on the summary index data.

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...