<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Export the raw source files in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Export-the-raw-source-files/m-p/561741#M10159</link>
    <description>&lt;P&gt;You can export the results of any search in CSV, JSON, or XML format. Just click on the export button just below the time picker.&lt;/P&gt;&lt;P&gt;To limit the amount of data you pull down you can limit your search results by excluding everything but _raw. You might also want to limit the number log files in your search as well.&lt;BR /&gt;&lt;BR /&gt;Example:&lt;BR /&gt;&amp;nbsp;index="con1_batch" source="*/PB00E5*/log/*.log" | fields + _raw |table _raw&lt;/P&gt;</description>
    <pubDate>Mon, 02 Aug 2021 19:31:20 GMT</pubDate>
    <dc:creator>codebuilder</dc:creator>
    <dc:date>2021-08-02T19:31:20Z</dc:date>
    <item>
      <title>Export the raw source files</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Export-the-raw-source-files/m-p/561738#M10158</link>
      <description>&lt;P&gt;Is there a way to export each raw source files?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Example of my search criteria:&lt;/P&gt;&lt;P&gt;&amp;nbsp;index="con1_batch" source="*/PB00E5*/log/*.log"&lt;/P&gt;&lt;P&gt;Top 10 Values Count %&lt;BR /&gt;/con7/var/batch/PB00E533/log/PB00E533.BatchEdbc.20210718031834.log 29,154 1.92%&lt;BR /&gt;/con7/var/batch/PB00E517/log/PB00E517.BatchEdbc.20210718031918.log 28,679 1.889%&lt;BR /&gt;/con7/var/batch/PB00E587/log/PB00E587.BatchEdbc.20210718031918.log 28,667 1.888%&lt;BR /&gt;/con7/var/batch/PB00E551/log/PB00E551.BatchEdbc.20210718031936.log 28,643 1.887%&lt;BR /&gt;/con7/var/batch/PB00E583/log/PB00E583.BatchEdbc.20210718031849.log 28,512 1.878%&lt;BR /&gt;/con7/var/batch/PB00E530/log/PB00E530.BatchEdbc.20210718031841.log 28,433 1.873%&lt;BR /&gt;/con7/var/batch/PB00E590/log/PB00E590.BatchEdbc.20210718032104.log 28,330 1.866%&lt;BR /&gt;/con7/var/batch/PB00E548/log/PB00E548.BatchEdbc.20210718031953.log 28,157 1.855%&lt;BR /&gt;/con7/var/batch/PB00E550/log/PB00E550.BatchEdbc.20210718031907.log 28,114 1.852%&lt;BR /&gt;/con7/var/batch/PB00E584/log/PB00E584.BatchEdbc.20210718031838.log 28,061 1.848%&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;There are 100+ source files. Can I download or export all the individual source file?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 18:26:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Export-the-raw-source-files/m-p/561738#M10158</guid>
      <dc:creator>sinha73</dc:creator>
      <dc:date>2021-08-02T18:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: Export the raw source files</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Export-the-raw-source-files/m-p/561741#M10159</link>
      <description>&lt;P&gt;You can export the results of any search in CSV, JSON, or XML format. Just click on the export button just below the time picker.&lt;/P&gt;&lt;P&gt;To limit the amount of data you pull down you can limit your search results by excluding everything but _raw. You might also want to limit the number log files in your search as well.&lt;BR /&gt;&lt;BR /&gt;Example:&lt;BR /&gt;&amp;nbsp;index="con1_batch" source="*/PB00E5*/log/*.log" | fields + _raw |table _raw&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 19:31:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Export-the-raw-source-files/m-p/561741#M10159</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2021-08-02T19:31:20Z</dc:date>
    </item>
  </channel>
</rss>

