Splunk Search

Appending search results to an existing report

Engager

I’d like to run a search once a day and append those search results to the previous day’s results. This way I can gradually build a big report showing data trends over time.

I can certainly schedule searches once per day but I’m not sure if there’s a way to continually append each day’s search to the previous day’s to generate a long term, ongoing report without running a search overall time consuming time / resources on the splunk server.

Tags (2)

Motivator

Have a look at the summary indexing section in the documents. This will be the most efficient way to build a big report showing data trends over time and is easy to setup and use.