Splunk Search

How do I run a Splunk search using R in the Splunk search bar and view the results on a dashboard?

m_vivek
Path Finder

I am very new to splunk .

Step 1: I want to run a splunk search on my local machine data and import the results into a csv/text file.
Step 2: Then I want to run an R script/Program on the obtained text file to create another excel file consisting of the results.

I have, at present, the R app (created by Rfujara) installed too.

Is there some way I can automate the whole process or integrate step1 and Step 2 into a single step so that I can directly view the results on a dashboard in Splunk by simple running a search query or by running an R script in the search bar?

Simply put, I want to be able to do something like

"the splunk search query to get necessary data" | r script to run/extract what I want from prev step | Splunk command to view results on dashboard

My primary issue lies in pointing the data obtained from the splunk search query into R directly, without having to change the file names in my R program manually each time I run it.

Thanks!

0 Karma

ngwells
Engager

Not sure if this will help but you can structure you script like this (Assuming you're pointing to R correctly):

index=_internal| r "getdim<-function(input){ return(aggregate(input[,'log_level'],by=list(input[,'log_level']),length))}; output=data.frame(getdim(input))"

Click "Visualization" tab to see bar chart of counts for Windows 7 _internal index. might need some ;'s to deploy in a dashboard.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Data Management Digest – June 2026

Welcome to the June 2026 edition of Data Management Digest! This month’s update is short and sweet, with a ...

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...