Is it possible to use a scheduled search within a dataset?


I like splunk's pivot table capabilities and am wondering if its possible to use a scheduled search within a dataset. You may ask, why not drop in the full query from the scheduled search into the datamodel then accelerate it. I've had issues with the accelerated data model consuming too much resource in the past and am trying to avoid it by using scheduled search to ensure it runs specific time at specific intervals. In going this route, I am missing out on the pivot UI

0 Karma

Esteemed Legend

A dataset can be a simple lookup file so all you need to do is setup a scheduled search and use | outputlookup or the built-in alerting function to save results to a lookup file. Put in whatever schedule suits you and update the lookup file that you have also setup as a dataset.

0 Karma


Hmmm. Is your scheduled search producing a reasonably small output, relative to the data being searched?

If so, then consider using your scheduled search to load a summary index, then basing your datamodel on the summary index data.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...