Splunk Search

Appending search results to an existing report


I’d like to run a search once a day and append those search results to the previous day’s results. This way I can gradually build a big report showing data trends over time.

I can certainly schedule searches once per day but I’m not sure if there’s a way to continually append each day’s search to the previous day’s to generate a long term, ongoing report without running a search overall time consuming time / resources on the splunk server.

Tags (2)


Have a look at the summary indexing section in the documents. This will be the most efficient way to build a big report showing data trends over time and is easy to setup and use.

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!