Hi,
I am trying to use Saved reports in my Splunk dashboard instead of inline searches...
I was able to use most recent report using |savedsearch = "searchname" in the query. But I need help to understand:
- How to run the query from history instead of the re-run of the searches.
- My report is executed every week and each execution has only one week worth of data. How to search based on all historic plus most recent reports in the dashboard. I need to do this for the week over week analysis.
thanks. Any help is highly appreciated!