<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Finding reports via the cli in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Finding-reports-via-the-cli/m-p/744684#M22124</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248209"&gt;@David_M&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Verify&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;reports&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;are&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;configured&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;generate&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;CSV&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;files.&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;In&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Splunk&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Web,&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;go&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Settings &lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;Searches, &lt;/SPAN&gt;&lt;SPAN class=""&gt;Reports, &lt;/SPAN&gt;&lt;SPAN class=""&gt;and &lt;/SPAN&gt;&lt;SPAN class=""&gt;Alerts&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;find&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;your&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;reports,&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;check&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;their&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;settings.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;P&gt;&lt;STRONG&gt;you have two choices:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;1) schedule an alert adding csv as attachment, to receive the csv via email.&lt;/P&gt;&lt;P&gt;2) you could schedule a report adding the outputcsv command at the end.&lt;/P&gt;&lt;P&gt;In this way, you save your report as csv in a pre-defined folder (not changeable!).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Tue, 22 Apr 2025 12:56:17 GMT</pubDate>
    <dc:creator>kiran_panchavat</dc:creator>
    <dc:date>2025-04-22T12:56:17Z</dc:date>
    <item>
      <title>Finding reports via the cli</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Finding-reports-via-the-cli/m-p/744681#M22121</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I setup 2 reports to run early this AM.&amp;nbsp; Looks like both reports ran according to splunk.&amp;nbsp; The problem I have now is finding the actual .csv files on the splunk server so I can scp them.&lt;/P&gt;&lt;P&gt;Thank...&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 12:19:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Finding-reports-via-the-cli/m-p/744681#M22121</guid>
      <dc:creator>David_M</dc:creator>
      <dc:date>2025-04-22T12:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Finding reports via the cli</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Finding-reports-via-the-cli/m-p/744682#M22122</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248209"&gt;@David_M&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By default, when a Splunk report generates a CSV file (e.g., using the outputcsv command or scheduled report export), the files are saved in the $SPLUNK_HOME/var/run/splunk/csv directory on the search head where the report was executed.&lt;/P&gt;&lt;P&gt;$SPLUNK_HOME is typically /opt/splunk on Linux systems, so the full path would be /opt/splunk/var/run/splunk/csv/.&lt;/P&gt;&lt;P&gt;Navigate to this directory using a terminal:&lt;/P&gt;&lt;P&gt;cd /opt/splunk/var/run/splunk/csv&lt;BR /&gt;ls -l&lt;/P&gt;&lt;P&gt;Look for files with a .csv extension. The file names might correspond to the report name, search job ID, or a custom name specified in the report configuration&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/Outputcsv" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/Outputcsv&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Please refer to this for more details, as highlighted by &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Is-there-anyway-to-generate-and-store-CSV-files-in-a-specific/td-p/465996" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/Is-there-anyway-to-generate-and-store-CSV-files-in-a-specific/td-p/465996&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 12:27:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Finding-reports-via-the-cli/m-p/744682#M22122</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-04-22T12:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: Finding reports via the cli</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Finding-reports-via-the-cli/m-p/744683#M22123</link>
      <description>&lt;P&gt;Hi Kiran,&lt;/P&gt;&lt;P&gt;Well I checked the directory mentioned in the posts and the files aren't there for some reason.&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 12:31:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Finding-reports-via-the-cli/m-p/744683#M22123</guid>
      <dc:creator>David_M</dc:creator>
      <dc:date>2025-04-22T12:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: Finding reports via the cli</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Finding-reports-via-the-cli/m-p/744684#M22124</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248209"&gt;@David_M&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Verify&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;reports&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;are&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;configured&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;generate&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;CSV&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;files.&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;In&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Splunk&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Web,&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;go&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Settings &lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;Searches, &lt;/SPAN&gt;&lt;SPAN class=""&gt;Reports, &lt;/SPAN&gt;&lt;SPAN class=""&gt;and &lt;/SPAN&gt;&lt;SPAN class=""&gt;Alerts&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;find&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;your&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;reports,&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;check&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;their&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;settings.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;P&gt;&lt;STRONG&gt;you have two choices:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;1) schedule an alert adding csv as attachment, to receive the csv via email.&lt;/P&gt;&lt;P&gt;2) you could schedule a report adding the outputcsv command at the end.&lt;/P&gt;&lt;P&gt;In this way, you save your report as csv in a pre-defined folder (not changeable!).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 22 Apr 2025 12:56:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Finding-reports-via-the-cli/m-p/744684#M22124</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-04-22T12:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: Finding reports via the cli</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Finding-reports-via-the-cli/m-p/744687#M22125</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248209"&gt;@David_M&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you use outputcsv, or some other method for exporting the csv such as using the "&lt;SPAN&gt;Output results to lookup" alert action?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;As previously mentioned - the output path for outputcsv is $SPLUNK_HOME&lt;SPAN&gt;/var/run/splunk/csv - however these files are&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Outputcsv#:~:text=not%20replicated%20across%20the%20cluster" target="_self"&gt;not replicated across the cluster&lt;/A&gt;&amp;nbsp;if you are running a SHC.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you're using the outputcsv, can you confirm you arent using&amp;nbsp;dispatch=true ? If you are you then your job will be in&amp;nbsp;$SPLUNK_HOME/var/run/splunk/dispatch/&amp;lt;job id&amp;gt;/csv&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 13:23:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Finding-reports-via-the-cli/m-p/744687#M22125</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-22T13:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: Finding reports via the cli</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Finding-reports-via-the-cli/m-p/744688#M22126</link>
      <description>&lt;P&gt;Hi Kiran,&lt;/P&gt;&lt;P&gt;Yea adding the outputcsv command fixed the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 13:50:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Finding-reports-via-the-cli/m-p/744688#M22126</guid>
      <dc:creator>David_M</dc:creator>
      <dc:date>2025-04-22T13:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: Finding reports via the cli</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Finding-reports-via-the-cli/m-p/744700#M22127</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248209"&gt;@David_M&lt;/a&gt;&amp;nbsp; Good to know that adding the outputcsv command resolved the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 16:40:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Finding-reports-via-the-cli/m-p/744700#M22127</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-04-22T16:40:55Z</dc:date>
    </item>
  </channel>
</rss>

