Splunk Search

How to schedule a report without it running

aohls
Contributor

I have a report I want to schedule, the results are populating a dataset. I want to set this to run every Sunday with week averages.
The issue I am having is I want to append the results to the populated table.

I am running my search to populate a few months of data but I want to convert it to run the past 7 days and append to my dataset.
I want to add the outputlookup to my search but then to save it I need to run it; I do not want the data in my dataset right now.
Can I somehow edit the report without needing to run the report and push data into my dataset?

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...