Reporting

Is it possible to use a scheduled search within a dataset?

spammenot66
Contributor

I like splunk's pivot table capabilities and am wondering if its possible to use a scheduled search within a dataset. You may ask, why not drop in the full query from the scheduled search into the datamodel then accelerate it. I've had issues with the accelerated data model consuming too much resource in the past and am trying to avoid it by using scheduled search to ensure it runs specific time at specific intervals. In going this route, I am missing out on the pivot UI

0 Karma

woodcock
Esteemed Legend

A dataset can be a simple lookup file so all you need to do is setup a scheduled search and use | outputlookup or the built-in alerting function to save results to a lookup file. Put in whatever schedule suits you and update the lookup file that you have also setup as a dataset.

0 Karma

DalJeanis
Legend

Hmmm. Is your scheduled search producing a reasonably small output, relative to the data being searched?

If so, then consider using your scheduled search to load a summary index, then basing your datamodel on the summary index data.

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...