Splunk Search

Appending search results to an existing report

rdsdnet
Engager

I’d like to run a search once a day and append those search results to the previous day’s results. This way I can gradually build a big report showing data trends over time.

I can certainly schedule searches once per day but I’m not sure if there’s a way to continually append each day’s search to the previous day’s to generate a long term, ongoing report without running a search overall time consuming time / resources on the splunk server.

Tags (2)

ftk
Motivator

Have a look at the summary indexing section in the documents. This will be the most efficient way to build a big report showing data trends over time and is easy to setup and use.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...