Splunk Search

scheduled searches

simo
Path Finder

Hi all,

I have two scheduled searches, is there the possibility to launch the second one at the end of the first?

can you help me? thanks for any answer

Best Regards,

Simone

Labels (1)
Tags (1)
0 Karma

hoaxm3
Path Finder
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Unfortunately there haven't been any official way to do it. If I recall right in https://ideas.splunk.com is request for this.

Anyhow you could try e.g. add the result of first schedule to kvstore / lookup and then in the beginning of the second schedule check it and run only if it is what you are expecting.

r. Ismo

simo
Path Finder

Hi,

my first search writes to an index using | collect index =

the second one from the index and produces a file | outputcsv mycsv

I'm trying to get them to run sequentially through cmd, it's possible?

Simone

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...