Reporting

schedule a search and output to store on output lookup.

n4niyaz
Explorer

is it possible to schedule a search for every 2 hours and output of the result is to save on output lookup. This output look up must be updated for every 2 hours, where the search runs.

0 Karma

gjanders
SplunkTrust
SplunkTrust

Are you saying

| outputlookup append=true

In a report?
The outputlookup command is documented here and you can of course run it regularly to append to your kvstore/csv.

Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...