<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sending data to AWS S3 from Splunk in Splunk Enterprise in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-AWS-S3-from-Splunk-in-Splunk-Enterprise/m-p/540087#M4961</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231558"&gt;@faisalshani001&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;One approach you can try is to export your data using Splunk REST API. Since you need to export the search results, I guess this works for you:&amp;nbsp;&lt;A href="https://www.splunk.com/en_us/blog/tips-and-tricks/exporting-large-results-sets-to-csv.html" target="_blank"&gt;Exporting Large Results Sets to CSV | Splunk&lt;/A&gt;&amp;nbsp;, and you can export on CSV, JSON or RAW format. Also, I think that using the API is pretty simple, since you can use python requests or event curl to create and export your search.&lt;/P&gt;&lt;P&gt;After saving the results into a file, you can upload it to the S3 bucket.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Feb 2021 12:54:03 GMT</pubDate>
    <dc:creator>alonsocaio</dc:creator>
    <dc:date>2021-02-16T12:54:03Z</dc:date>
    <item>
      <title>Sending data to AWS S3 from Splunk in Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-AWS-S3-from-Splunk-in-Splunk-Enterprise/m-p/540054#M4954</link>
      <description>&lt;P&gt;Hi Members, So I am quite new to splunk and I need to send the splunk search results to AWS S3 bucket. I have tried some apps from splunkbase but they are not working. (APP NO 5273 &amp;amp; Event Push by Deductiv).&lt;BR /&gt;&lt;BR /&gt;Can someone guide me here what approach I should follow to make such a pipeline?&amp;nbsp;&lt;BR /&gt;(Since we are working on just of POC we cant use the Splunk DSP, I am looking for an open source or free approach with minimal cost) .&lt;BR /&gt;&lt;BR /&gt;Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 07:22:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-AWS-S3-from-Splunk-in-Splunk-Enterprise/m-p/540054#M4954</guid>
      <dc:creator>faisalshani001</dc:creator>
      <dc:date>2021-02-16T07:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: Sending data to AWS S3 from Splunk in Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-AWS-S3-from-Splunk-in-Splunk-Enterprise/m-p/540087#M4961</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231558"&gt;@faisalshani001&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;One approach you can try is to export your data using Splunk REST API. Since you need to export the search results, I guess this works for you:&amp;nbsp;&lt;A href="https://www.splunk.com/en_us/blog/tips-and-tricks/exporting-large-results-sets-to-csv.html" target="_blank"&gt;Exporting Large Results Sets to CSV | Splunk&lt;/A&gt;&amp;nbsp;, and you can export on CSV, JSON or RAW format. Also, I think that using the API is pretty simple, since you can use python requests or event curl to create and export your search.&lt;/P&gt;&lt;P&gt;After saving the results into a file, you can upload it to the S3 bucket.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 12:54:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-AWS-S3-from-Splunk-in-Splunk-Enterprise/m-p/540087#M4961</guid>
      <dc:creator>alonsocaio</dc:creator>
      <dc:date>2021-02-16T12:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Sending data to AWS S3 from Splunk in Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-AWS-S3-from-Splunk-in-Splunk-Enterprise/m-p/540098#M4965</link>
      <description>&lt;P&gt;Thanks for replying&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/156088"&gt;@alonsocaio&lt;/a&gt;&amp;nbsp;. But I need to create an automated pipeline which should send data to AWS S3 automatically. Means when one writes the SPL query on splunk searc &amp;amp; reporting bar the result should be exported to an csv file and send to AWS S3. Any idea how to create this pipeline?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 13:39:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-AWS-S3-from-Splunk-in-Splunk-Enterprise/m-p/540098#M4965</guid>
      <dc:creator>faisalshani001</dc:creator>
      <dc:date>2021-02-16T13:39:31Z</dc:date>
    </item>
  </channel>
</rss>

