You can schedule searches to run on a regular basis.
|Report||After you save a search as a report, you can convert that report into a scheduled report. A scheduled report is a report that runs on a scheduled interval, and which can trigger an action each time the report runs. There are two actions available for scheduled reports: Send email and Run a script.||See Schedule reports in the Reporting Manual.|
|Dashboard panel||There are several options to create a scheduled report:
||See Working with dashboard panels in the Dashboards and Visualizations manual.|
|Alert||You can create a scheduled alert to search for events on a regular schedule. You can configure scheduling, trigger conditions, and throttling to customize the alert.||See Create scheduled alerts in the Alerting Manual.|
About federated search
This documentation applies to the following versions of Splunk Cloud™: 7.0.13, 7.2.9, 7.2.10, 8.0.2006, 8.0.2007, 8.1.2008, 8.1.2009, 8.1.2011, 8.1.2012 (latest FedRAMP release), 8.1.2101, 8.1.2103, 8.2.2104, 8.2.2105