| savedquery Q1 -> this runs okay
| savedquery Q1 | savedquery Q2 -> not okay. splunk error.
| savedquery Q1, Q2 -> not okay, splunk error.
| savedsearch Q1 | append [savedsearch Q2 ] | append [savedsearch Q3 ] | append [savedsearch Q4] --> okay and runs, but once the first one runs, not the rest.
Is it possible run a batch of saved queries in splunk?
Is automation using python, rest the only choice?
I am trying to keep it simple if possible. Anything I can try?
First the 2 queries need to be run one after the other since the first creates a csv files which second query reads. There needs to be serial than parallel execution.
Is there a serial search version of multisearch which runs queries at the same time?
Its good if I can run the rest command from splunk itself, 2 queries one after the other, preferable checking the status for successful completion.
| rest /servicesNS/admin/search/saved/searches | search title="*threshold"
Then you can add
| map maxsearches=20 search="| savedsearch \"$title$\" | eval savedsearch=\"$title$\" "
The 2 queries have different earliest and latest values and cant be run with the same time values. It looks like that is still a constraint and the above wont work.
Any other suggestions?