Splunk Search

Scheduled search in a dashboard

bagarwal
Path Finder

Hello Everyone,

I have created a dashboard and wants the result for last 7 days; and want to schedule it and run every day , say at 9:30 pm . So, next morning when I open the dashboard it gives me the result immediately. I didn't find any option . For the report I know there are options. Is it something , we need to add cron schedule in xml file of the dashboard .

Kindly help.

Thanks in advance.

Best Regards,

Binay Agarwal

0 Karma
1 Solution

mayurr98
Super Champion

Hello @bagarwal

Dashboard panels don't really cache information. They run each panels search at the time of the dashboard loading. However, you can schedule a report and import the results of the scheduled report into a dashboard panel. For instance, if you scheduled a report to run once a day at 00:00 then the dashboard would show the results of the scheduled report.

let me know if this helps!

View solution in original post

0 Karma

mayurr98
Super Champion

Hello @bagarwal

Dashboard panels don't really cache information. They run each panels search at the time of the dashboard loading. However, you can schedule a report and import the results of the scheduled report into a dashboard panel. For instance, if you scheduled a report to run once a day at 00:00 then the dashboard would show the results of the scheduled report.

let me know if this helps!

0 Karma

bagarwal
Path Finder

Thanks @mayurr98 for the help.

0 Karma

reynlds
Explorer

Is it possible to use the report through the dashboard as a "search base"? I'd like to have a couple of input fields that query the report as part of the dashboard, including a date picker. My users don't have access to my index, but I could allow access to the report.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...