Getting Data In

Base Searches for Dashboards using Splunk Metrics

splunkninga2
New Member

Hi all,

My team recently got metric data into Splunk and I created several dashboards with various drop down tokens for metric names as well as host. My next step was to try and create a logical base search with post processing searches to reduce the amount of concurrent searches running within the panels. I've been having a heck of a time getting a proper base search to work when it struck me:

These metric searches on the panels almost always complete in 1 second and there aren't too many metric points being generated per day. Are base searches even worth it for this type of data? I know that base searches is a best practice for dashboards, but these panels still load almost instantly even when concurrent dashboards are being run. Trying to get some potential insight before I go down rabbit holes again to get a base search and post processing searches to work.

Appreciate any feedback 😄

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...