Splunk Search

Scheduled search in a dashboard

bagarwal
Path Finder

Hello Everyone,

I have created a dashboard and wants the result for last 7 days; and want to schedule it and run every day , say at 9:30 pm . So, next morning when I open the dashboard it gives me the result immediately. I didn't find any option . For the report I know there are options. Is it something , we need to add cron schedule in xml file of the dashboard .

Kindly help.

Thanks in advance.

Best Regards,

Binay Agarwal

0 Karma
1 Solution

mayurr98
Super Champion

Hello @bagarwal

Dashboard panels don't really cache information. They run each panels search at the time of the dashboard loading. However, you can schedule a report and import the results of the scheduled report into a dashboard panel. For instance, if you scheduled a report to run once a day at 00:00 then the dashboard would show the results of the scheduled report.

let me know if this helps!

View solution in original post

0 Karma

mayurr98
Super Champion

Hello @bagarwal

Dashboard panels don't really cache information. They run each panels search at the time of the dashboard loading. However, you can schedule a report and import the results of the scheduled report into a dashboard panel. For instance, if you scheduled a report to run once a day at 00:00 then the dashboard would show the results of the scheduled report.

let me know if this helps!

0 Karma

bagarwal
Path Finder

Thanks @mayurr98 for the help.

0 Karma

reynlds
Explorer

Is it possible to use the report through the dashboard as a "search base"? I'd like to have a couple of input fields that query the report as part of the dashboard, including a date picker. My users don't have access to my index, but I could allow access to the report.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...