Hello,
I'm still very new to Splunk.
I have a dashboard with a search, and users can choose between the last 24 hours, the last 30 days, the last 90 days, or the last year.
For the last 24 hours, it should never get too slow, and to let users the 'freshest' data, I leave it as an inline search. However, for the longer searches, users are mainly looking at trends, and so I thought the best way to speed everything up would be with a scheduled search that runs say, once a day.
This works absolutely fine, but I don't want to make a scheduled search for 30 days, another scheduled search for 90 days and yet another for a year. I assume there's a way to simply scheduled a search for a year to run everyday, and for the smaller time ranges i could just pick my results from it. I've been searching a lot about datasets, data models, scheduled searches but I can't quite find the best way to do this.
Thank you!
... View more