Splunk Search

How to create a dashboard with one search that can produce results for both today and yesterday?

Isiegniel
New Member

Hello,

I want to create a dashboard with 2 searches. Search A should show a search result from today.
Search B should show a search Result from yesterday.

Is there a way to give the results from search A to B so that B doesn't need to search again?

Tags (3)
0 Karma
1 Solution

skoelpin
SplunkTrust
SplunkTrust

Yes it's called post processing

"If your dashboard contains panels that run similar searches, you can save search resources by creating a base search for the dashboard. Panels in the dashboard can use a post-process search to further modify the results of a base search. The base search can be a global search for the dashboard or any other search within the dashboard."

http://docs.splunk.com/Documentation/Splunk/6.2.5/Viz/Savedsearches#Post-process_searches

View solution in original post

skoelpin
SplunkTrust
SplunkTrust

Yes it's called post processing

"If your dashboard contains panels that run similar searches, you can save search resources by creating a base search for the dashboard. Panels in the dashboard can use a post-process search to further modify the results of a base search. The base search can be a global search for the dashboard or any other search within the dashboard."

http://docs.splunk.com/Documentation/Splunk/6.2.5/Viz/Savedsearches#Post-process_searches

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...