Splunk Search

Appending search results to an existing report

rdsdnet
Engager

I’d like to run a search once a day and append those search results to the previous day’s results. This way I can gradually build a big report showing data trends over time.

I can certainly schedule searches once per day but I’m not sure if there’s a way to continually append each day’s search to the previous day’s to generate a long term, ongoing report without running a search overall time consuming time / resources on the splunk server.

Tags (2)

ftk
Motivator

Have a look at the summary indexing section in the documents. This will be the most efficient way to build a big report showing data trends over time and is easy to setup and use.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...