I am trying to essentially gather information of a pretty large query and count it every day, and then display this total count every day in a timechart so that we can track the change overtime. The problem I have is that the calculations are based on a CSV file that are overwritten every day so I am not sure how to go about storing historical data. The best thing I can think of doing is to append to a CSV the time and the calculated count every day but I wasn't sure if there was an easier way to do this.
You're looking for summary indexing: http://docs.splunk.com/Documentation/Splunk/6.2.4/Knowledge/Usesummaryindexing
You're looking for summary indexing: http://docs.splunk.com/Documentation/Splunk/6.2.4/Knowledge/Usesummaryindexing