<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: /services/search/jobs/export ignores required fields in CSV in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/services-search-jobs-export-ignores-required-fields-in-CSV/m-p/30082#M5222</link>
    <description>&lt;P&gt;I think I made progress. The API is very very picky as to the order of piped commands...&lt;/P&gt;

&lt;P&gt;After many many permutations this got me somewhere:&lt;/P&gt;

&lt;P&gt;search * | head 10 | table _time,mycolumn1,event_code,from_ip,from_port&lt;/P&gt;

&lt;P&gt;The CSV output is still not honoring the field order (I did try to pipe it to the 'fields' command, which didn't affect CSV output still). So, _time column is somewhere in the middle of the output, and not the first one. I'll try reformatting it, maybe it will agree to behave better when treated as a custom field &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Another issue is the string values for columns are wrapped in double quotes, which seems really redundant when there's no need for that at all (e.g. simple values).&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 13:52:51 GMT</pubDate>
    <dc:creator>aperepel</dc:creator>
    <dc:date>2020-09-28T13:52:51Z</dc:date>
    <item>
      <title>/services/search/jobs/export ignores required fields in CSV</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/services-search-jobs-export-ignores-required-fields-in-CSV/m-p/30081#M5221</link>
      <description>&lt;P&gt;The doc for the /jobs/export mentions the 'rf' parameter (v5.0.2). However, it is ignored by the REST endpoint. E.g. for this URL: &lt;A href="https://example.com/services/search/jobs/export?search=search+*+index%3D%22somename%22++%7C+head+50&amp;amp;output_mode=csv&amp;amp;rf=event_code"&gt;https://example.com/services/search/jobs/export?search=search+*+index%3D%22somename%22++%7C+head+50&amp;amp;output_mode=csv&amp;amp;rf=event_code&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I expect it to return an event_code field, but it just dumps raw set of meta fields (host, time, _raw, etc.). NONE of the actual extracted fields which work great in the UI.&lt;/P&gt;

&lt;P&gt;How can I set up the CSV export to contain only the fields I want?&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2013 17:07:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/services-search-jobs-export-ignores-required-fields-in-CSV/m-p/30081#M5221</guid>
      <dc:creator>aperepel</dc:creator>
      <dc:date>2013-05-10T17:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: /services/search/jobs/export ignores required fields in CSV</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/services-search-jobs-export-ignores-required-fields-in-CSV/m-p/30082#M5222</link>
      <description>&lt;P&gt;I think I made progress. The API is very very picky as to the order of piped commands...&lt;/P&gt;

&lt;P&gt;After many many permutations this got me somewhere:&lt;/P&gt;

&lt;P&gt;search * | head 10 | table _time,mycolumn1,event_code,from_ip,from_port&lt;/P&gt;

&lt;P&gt;The CSV output is still not honoring the field order (I did try to pipe it to the 'fields' command, which didn't affect CSV output still). So, _time column is somewhere in the middle of the output, and not the first one. I'll try reformatting it, maybe it will agree to behave better when treated as a custom field &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Another issue is the string values for columns are wrapped in double quotes, which seems really redundant when there's no need for that at all (e.g. simple values).&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:52:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/services-search-jobs-export-ignores-required-fields-in-CSV/m-p/30082#M5222</guid>
      <dc:creator>aperepel</dc:creator>
      <dc:date>2020-09-28T13:52:51Z</dc:date>
    </item>
  </channel>
</rss>

