Splunk Search

how can you run one search and share that data with multiple panels

TDR57
Explorer

How can or is there a way of running one search and sharing the resulting data amongst multiple panels in a Dashboard. I am trying to reduce the number of searches that is performed
in my dashboard

0 Karma
1 Solution

niketn
Legend

@TDR57, you should check out Post Processing searches (carefully go through best practices as well). There are couple of Post Processing Examples covered in Splunk Dashboard Examples app as well.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

kyaparla
Path Finder

Yes, it can be done thru post processing searches.

Please check this link for more info.

http://docs.splunk.com/Documentation/Splunk/7.0.2/Viz/Savedsearches#Post-process_searches

0 Karma

niketn
Legend

@TDR57, you should check out Post Processing searches (carefully go through best practices as well). There are couple of Post Processing Examples covered in Splunk Dashboard Examples app as well.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...