Splunk Search

How to create a dashboard with one search that can produce results for both today and yesterday?

Isiegniel
New Member

Hello,

I want to create a dashboard with 2 searches. Search A should show a search result from today.
Search B should show a search Result from yesterday.

Is there a way to give the results from search A to B so that B doesn't need to search again?

Tags (3)
0 Karma
1 Solution

skoelpin
SplunkTrust
SplunkTrust

Yes it's called post processing

"If your dashboard contains panels that run similar searches, you can save search resources by creating a base search for the dashboard. Panels in the dashboard can use a post-process search to further modify the results of a base search. The base search can be a global search for the dashboard or any other search within the dashboard."

http://docs.splunk.com/Documentation/Splunk/6.2.5/Viz/Savedsearches#Post-process_searches

View solution in original post

skoelpin
SplunkTrust
SplunkTrust

Yes it's called post processing

"If your dashboard contains panels that run similar searches, you can save search resources by creating a base search for the dashboard. Panels in the dashboard can use a post-process search to further modify the results of a base search. The base search can be a global search for the dashboard or any other search within the dashboard."

http://docs.splunk.com/Documentation/Splunk/6.2.5/Viz/Savedsearches#Post-process_searches

Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...