How can I save a query data so that it does not get loaded everytime


I would like to save a query result, for example: for a particular month. I don't want splunk to load the page and fetch the data everytime the page is loaded.

I need to get the results saved so that I can see the results instantaneously.Similar to canned report.

You could schedule your search to run once a month and output to a CSV. Subsequent searches can pull the data from the monthly CSV.


Musskopf's comment is a good suggestion. You might also consider saving the query resuls in a summary index and pulling from the index to load the page.

You'll need to save your search as a report and schedule the report to run. Once it ran at least once, use the command " |loadjob "admin:search:report_name" " to get the results...

