Splunk Search

How to create a dashboard with one search that can produce results for both today and yesterday?

New Member

Hello,

I want to create a dashboard with 2 searches. Search A should show a search result from today.
Search B should show a search Result from yesterday.

Is there a way to give the results from search A to B so that B doesn't need to search again?

Tags (3)
0 Karma
1 Solution

SplunkTrust
SplunkTrust

Yes it's called post processing

"If your dashboard contains panels that run similar searches, you can save search resources by creating a base search for the dashboard. Panels in the dashboard can use a post-process search to further modify the results of a base search. The base search can be a global search for the dashboard or any other search within the dashboard."

http://docs.splunk.com/Documentation/Splunk/6.2.5/Viz/Savedsearches#Post-process_searches

View solution in original post

SplunkTrust
SplunkTrust

Yes it's called post processing

"If your dashboard contains panels that run similar searches, you can save search resources by creating a base search for the dashboard. Panels in the dashboard can use a post-process search to further modify the results of a base search. The base search can be a global search for the dashboard or any other search within the dashboard."

http://docs.splunk.com/Documentation/Splunk/6.2.5/Viz/Savedsearches#Post-process_searches

View solution in original post

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!