You can schedule searches to run on a regular basis.
|Report||After you save a search as a report, you can convert that report into a scheduled report. A scheduled report is a report that runs on a scheduled interval, and which can trigger an action each time the report runs. There are two actions available for scheduled reports: Send email and Run a script.||See Schedule reports in the Reporting Manual.|
|Dashboard panel||There are several options to create a scheduled report:
||See Working with dashboard panels in the Dashboards and Visualizations manual.|
|Alert||You can create a scheduled alert to search for events on a regular schedule. You can configure scheduling, trigger conditions, and throttling to customize the alert.||See Create scheduled alerts in the Alerting Manual.|
About federated search
This documentation applies to the following versions of Splunk Cloud Platform™: 8.1.2103, 8.2.2106, 8.2.2107, 8.2.2105, 8.2.2109, 8.2.2111, 8.2.2112, 8.2.2201 (latest FedRAMP release), 8.2.2202, 8.2.2203