In order to send the search results to another location, you can use the search command: outputcsv.
Documented at: http://www.splunk.com/base/Documentation/latest/SearchReference/Outputcsv
keeping the saved search artifact for longer in the $SPLUNK_HOME/var/run/splunk/dispatch dir, is done using the dispatch.ttl parameter in the saved search configuration. (It can get a bit complicated if there are actions that are triggered from the search).
See: http://www.splunk.com/base/Documentation/latest/Admin/Savedsearchesconf
The default value for keeping the saved searches results is twice the time period.
... View more