In the last few Parts of this tutorial, you learned the basics of searching using the Splunk software, how to use a subsearch, and how to add fields from lookup tables. Part 6 shows you how to save and share your searches and explores more detailed search examples.
The remaining Parts in this tutorial depend on you completing the steps in the section Enabling field lookups.
If you do not configure the field lookups, the searches will not produce the correct results.
Save a search as a report
Reports are created whenever you save a search. After you create a report, you can do a lot with it.
- Set the time range to Last 7 days and run the following search.
This is the same search that you ran in the section Search with field lookups.sourcetype=access_* status=200 action=purchase [search sourcetype=access_* status=200 action=purchase | top limit=1 clientip | table clientip] | stats count AS "Total Purchased", dc(productId) AS "Total Products", values(productName) AS "Product Names" BY clientip | rename clientip AS "VIP Customer"
If your search does not return results, increase the time range of the search. For example, you can run this search over the time range Last 30 days or All Time.
- In the Save As Report dialog box for Title type
VIP Customer
. - For Time Range Picker, click Yes.
When you include a Time range picker in a report, it gives you the option of running the report with a different time range. - Click Save.
A confirmation dialog box opens confirming that your report has been created. From this dialog box you can perform the following actions.- Continue Editing. To refine the search and report format.
- Add to Dashboard. To add the report to a new or existing dashboard.
- View. To view the report.
View and edit reports
You can view and edit reports that you have saved. You edit a report directly from within the report.
- Look at the time range picker, located at the upper left corner of the window.
With the Time range picker, you can change the time period to run this search. For example, you can use the time range picker to run this search for the VIP Customer Week to date, Last 60 minutes, or Last 24 hours just by selecting the Preset time range or defining a custom time range.
You can access your reports using the App bar.
- For the VIP Customer report, under Actions click Edit.
- In the Edit Permissions dialog box, set Display For to App.
The display expands to show more settings.
Next step
Let's explore some other search examples, work with chart visualizations, and save the searches as reports, starting with Create a basic chart.
See also
In the Reporting Manual
Search with field lookups | Create a basic chart |
This documentation applies to the following versions of Splunk® Enterprise: 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10, 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.1.8, 8.1.9, 8.1.10, 8.1.11, 8.1.12, 8.1.13, 8.1.14
Feedback submitted, thanks!