Reporting

Do Reports contain results of past searches or are they only a reference to a saved search query?

koocies
Path Finder

I'm new to Splunk and I find Splunk reports confusing.

In other SIEMS a report is the results of a previously ran query. However, it seems to be that reports are saved search queries without results of previous runs. So, when I click a report name it seems to be rerunning the query and now showing results of a previous run.

Are my assumptions & understand of reports correct?

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's most common for a report to run a query and display the results.  It is possible, however, to create a report that displays the results of a previously-run saved search.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...