<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;Export results...&amp;quot; output blank when using inputlookup in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/quot-Export-results-quot-output-blank-when-using-inputlookup/m-p/56132#M10962</link>
    <description>&lt;P&gt;Additional info: It appears this may be a problem with Splunk exporting data when there are no "events" (such as when using the inputlookup command). Again, this has only been happening since the upgrade from the 4.2.x line to the 5.0.x line.&lt;/P&gt;

&lt;P&gt;I'm not able to reproduce the issue with a fresh 5.0.4 error, so I assume this is a configuration error. Looking through the logs in _internal I don't see any obvious errors (what should I be looking for for csv export errors?).&lt;/P&gt;</description>
    <pubDate>Thu, 05 Sep 2013 23:34:08 GMT</pubDate>
    <dc:creator>rtadams89</dc:creator>
    <dc:date>2013-09-05T23:34:08Z</dc:date>
    <item>
      <title>"Export results..." output blank when using inputlookup</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/quot-Export-results-quot-output-blank-when-using-inputlookup/m-p/56129#M10959</link>
      <description>&lt;P&gt;If I perform a search for:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=myindex | table field1, field2, field3
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and then use the "Actions" menu to "Export results", I can get a csv with 3 columns and as many lines as there were events returned by the search.&lt;/P&gt;

&lt;P&gt;On the other hand, if I run this search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| inputlookup test.csv | table field1, field2, field3
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and then attempt to "Export results", the output (csv, xml, or json) is always empty (no column headers or data). The test.csv file contains data and the search displays data within the Splunk web GUI, just nothing when attempting to export.&lt;/P&gt;

&lt;P&gt;Both of the above search would allow me to export data when I was running 4.2.3; this problem only appears after upgrading to 5.0.4.&lt;/P&gt;

&lt;P&gt;Any ideas what the fix is?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2013 22:35:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/quot-Export-results-quot-output-blank-when-using-inputlookup/m-p/56129#M10959</guid>
      <dc:creator>rtadams89</dc:creator>
      <dc:date>2013-09-05T22:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: "Export results..." output blank when using inputlookup</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/quot-Export-results-quot-output-blank-when-using-inputlookup/m-p/56130#M10960</link>
      <description>&lt;P&gt;Hi Rtadams89,&lt;/P&gt;

&lt;P&gt;I've just tested in 5.0.1 &amp;amp; 5.0.4 and am unable to replicate the issue you are reporting. The only thing that I can see wrong with what you have described is a missing pipe character at the start of your second command:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| inputlookup test.csv | table field1, field2, field3
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 05 Sep 2013 23:29:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/quot-Export-results-quot-output-blank-when-using-inputlookup/m-p/56130#M10960</guid>
      <dc:creator>rturk</dc:creator>
      <dc:date>2013-09-05T23:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: "Export results..." output blank when using inputlookup</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/quot-Export-results-quot-output-blank-when-using-inputlookup/m-p/56131#M10961</link>
      <description>&lt;P&gt;Sorry, that was a typo in my original post. In my testing, I DO have a leading pipe.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2013 23:31:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/quot-Export-results-quot-output-blank-when-using-inputlookup/m-p/56131#M10961</guid>
      <dc:creator>rtadams89</dc:creator>
      <dc:date>2013-09-05T23:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: "Export results..." output blank when using inputlookup</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/quot-Export-results-quot-output-blank-when-using-inputlookup/m-p/56132#M10962</link>
      <description>&lt;P&gt;Additional info: It appears this may be a problem with Splunk exporting data when there are no "events" (such as when using the inputlookup command). Again, this has only been happening since the upgrade from the 4.2.x line to the 5.0.x line.&lt;/P&gt;

&lt;P&gt;I'm not able to reproduce the issue with a fresh 5.0.4 error, so I assume this is a configuration error. Looking through the logs in _internal I don't see any obvious errors (what should I be looking for for csv export errors?).&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2013 23:34:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/quot-Export-results-quot-output-blank-when-using-inputlookup/m-p/56132#M10962</guid>
      <dc:creator>rtadams89</dc:creator>
      <dc:date>2013-09-05T23:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: "Export results..." output blank when using inputlookup</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/quot-Export-results-quot-output-blank-when-using-inputlookup/m-p/56133#M10963</link>
      <description>&lt;P&gt;Looks like there was an issue with the xml views for the search app. The XML views worked in the 4.x line, but when upgraded to 5.x, the xml persisted and had the Export function referencing the events endpoint instead of the results endpoint. I went in an manually deleted the xml files from apps/search/local/data/ui/views and the problem is now fixed.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2013 16:12:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/quot-Export-results-quot-output-blank-when-using-inputlookup/m-p/56133#M10963</guid>
      <dc:creator>rtadams89</dc:creator>
      <dc:date>2013-09-06T16:12:19Z</dc:date>
    </item>
  </channel>
</rss>

