Splunk Search

Is it possible to perform a tstats from an accelerated savedsearch?

ericg57
Engager

I am asking because I attempted to use "savedsearch=" as a command after a | tstats much like calling a "datamodel=" , and I now see that the "savedsearch=" is highlighhted as if it should be as if it is an accepted command.

|tstats savedsearch=mysavedsearch

Tags (1)
0 Karma

vinod94
Contributor

Hi @ericg57 ,

You can run a Report Name through savedsearch command. You can make it work like this.

| savedsearch "Report Name"

You can also use tstats in a "Report Name" (ie in the search query of Report) and then call it from savedsearch.

For better understanding of savedsearch=

you can check this doc ... hope this clears your concern

https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/Loadjob

0 Karma

ericg57
Engager

Correction: and I now see that the "savedsearch=" is highlighhted as if it should be an accepted command.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...