<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: pushing data to new csv in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/pushing-data-to-new-csv/m-p/460000#M79409</link>
    <description>&lt;P&gt;Hikavyamohan,&lt;BR /&gt;
you have a continuous monitoring, so the new row is read and indexed by Splunk, to add this row to your csv you have two choices:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;override the csv with all the results of your search,&lt;/LI&gt;
&lt;LI&gt;add only the new row.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;The first choice is the easiest because you have to run your search and use the command outputlookup at the end (see &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.2/SearchReference/Outputlookup"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.2/SearchReference/Outputlookup&lt;/A&gt; ).&lt;/P&gt;

&lt;P&gt;The second requires that you filter the results of your search using the existing csv.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 14 Oct 2019 11:23:01 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2019-10-14T11:23:01Z</dc:date>
    <item>
      <title>pushing data to new csv</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/pushing-data-to-new-csv/m-p/459999#M79408</link>
      <description>&lt;P&gt;I have a csv where there are 5 columns and the number of rows is 1000. I have indexed that csv as continuous monitoring. If a new row is added into the same csv it should be automatically pushed to new csv which I have created in Splunk. this can be done based on the any calculation. Is this possible?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2019 10:39:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/pushing-data-to-new-csv/m-p/459999#M79408</guid>
      <dc:creator>kavyamohan</dc:creator>
      <dc:date>2019-10-14T10:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: pushing data to new csv</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/pushing-data-to-new-csv/m-p/460000#M79409</link>
      <description>&lt;P&gt;Hikavyamohan,&lt;BR /&gt;
you have a continuous monitoring, so the new row is read and indexed by Splunk, to add this row to your csv you have two choices:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;override the csv with all the results of your search,&lt;/LI&gt;
&lt;LI&gt;add only the new row.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;The first choice is the easiest because you have to run your search and use the command outputlookup at the end (see &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.2/SearchReference/Outputlookup"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.2/SearchReference/Outputlookup&lt;/A&gt; ).&lt;/P&gt;

&lt;P&gt;The second requires that you filter the results of your search using the existing csv.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2019 11:23:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/pushing-data-to-new-csv/m-p/460000#M79409</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-10-14T11:23:01Z</dc:date>
    </item>
  </channel>
</rss>

