Yes you can do from backend in Splunk search head server
Need to move Dashboard xml file in splunk/etc/apps///data/ui/views
And update default.meta file under /metadata/default.meta file as
[views/XXXXXX_dashboard]
access = read : [ user], write : [ poweruser ]
export = none
owner = XXXXX
version = 6.5.1
modtime = 45356436543674
... View more
just form the concatenation of the result data and keep as _raw data custom in summary index
this is workaround basically which is also good solution
....... | eval newraw=newtime . " report=\"" . report. "\",logtime=\"" . logtime . "\",origsource=\"" ...
| eval _raw=newraw | collect index=my_summary
... View more