It was suggested by our Splunk admin(s) that this is the best way to do it, since they don't want to expose the full index (all sources) to the end users. If there is a way to setup a role with only the access needed for the source, I could bypass this whole scheduled report setup, but they've said that is not possible in our current environment. Using a scheduled report as a base for the search in the dashboard was all that was offered.
I read through the link you provided, but am unclear as to whether the collect index is created on-the-fly, or if I'll need them to create it for me.
... View more