Splunk Search

How to collect data from a scheduled run by single base search followed by two different search?

Thulasinathan_M
Communicator

Hi Splunk Experts,

I've a dashboard, where I have a base search and use the base search results in two different Panels to collect data to sourcetype, both panel query performs two extreme different kind of operations. Currently I'm running them manually, but I want to run this in a scheduled mode. Is it possible, I thought of Saved Search, but I'm not sure whether that's the right solution. Could you please assist on better approach. Thanks in advance!!

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

here https://docs.splunk.com/Documentation/Splunk/latest/Viz/Savedsearches#Referenced_report_searches is example how to use ref (report/savedsearch) on your dashboard.

r. Ismo

Thulasinathan_M
Communicator

Hi @isoutamo, Thank you, but is it possible to schedule the Dashboard every 15 mins to collect data to sourcetype.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

You can add a refresh option to it and then is do a new searches for all panel or just for one, depend on where you will put that option. Works both SXML and Dashboard Studio with different syntax.

If I recall right this will work little bit different with Splunk 9.1 (when it comes out) with base searches. Also if your reports has scheduled regularly and you are using those then it could be that you will get old data time by time.

See more dashboard or form

Thulasinathan_M
Communicator

Thanks, that done the trick but this is feasible only if the dashboard is in open state. But I want to this to perform even if the dashboard is not in open state.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...