<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to filter CLI export in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Unable-to-filter-CLI-export/m-p/106601#M2454</link>
    <description>&lt;P&gt;Hello!&lt;/P&gt;

&lt;P&gt;I'm trying to export a subset of logs indexed on one indexer, and then import them into another.  I'm attempting to use the cli export tool to do this, and am running into issues.&lt;/P&gt;

&lt;P&gt;If I run the following:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;./splunk export eventdata -index main -dir /tmp/export&lt;/CODE&gt; &lt;/P&gt;

&lt;P&gt;then I get a successful export of everything that has been indexed by the server.  Unfortunately, this is far more data than I actually want to export.  To try and narrow it down, I'm using further export flags, but they don't appear to be working at all.  I'm trying to get a specific set of log files from specific hosts.  &lt;/P&gt;

&lt;P&gt;Using commands like the following:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;./splunk export eventdata -index main -dir /tmp/export -host HOSTNAME&lt;/CODE&gt; &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;./splunk export eventdata -index main -dir /tmp/export -source LOGFILEPATH&lt;/CODE&gt; &lt;/P&gt;

&lt;P&gt;I simply get nothing exported.  I've verified that the host name and logfile info is correct, so I'm at a loss as to what is causing it to return nothing.  I am assuming that the -host flag is used to denote the forwarder that the logs originated from, and that the -source is the full path of the logfile.  (Ex:  'D:\apache-tomcat-6.0.32\bin\server.log'.  I have tried it both escaped and not)  &lt;/P&gt;

&lt;P&gt;Has anyone else run into this issue?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 08 Nov 2011 18:50:43 GMT</pubDate>
    <dc:creator>emiller42</dc:creator>
    <dc:date>2011-11-08T18:50:43Z</dc:date>
    <item>
      <title>Unable to filter CLI export</title>
      <link>https://community.splunk.com/t5/Reporting/Unable-to-filter-CLI-export/m-p/106601#M2454</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;

&lt;P&gt;I'm trying to export a subset of logs indexed on one indexer, and then import them into another.  I'm attempting to use the cli export tool to do this, and am running into issues.&lt;/P&gt;

&lt;P&gt;If I run the following:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;./splunk export eventdata -index main -dir /tmp/export&lt;/CODE&gt; &lt;/P&gt;

&lt;P&gt;then I get a successful export of everything that has been indexed by the server.  Unfortunately, this is far more data than I actually want to export.  To try and narrow it down, I'm using further export flags, but they don't appear to be working at all.  I'm trying to get a specific set of log files from specific hosts.  &lt;/P&gt;

&lt;P&gt;Using commands like the following:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;./splunk export eventdata -index main -dir /tmp/export -host HOSTNAME&lt;/CODE&gt; &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;./splunk export eventdata -index main -dir /tmp/export -source LOGFILEPATH&lt;/CODE&gt; &lt;/P&gt;

&lt;P&gt;I simply get nothing exported.  I've verified that the host name and logfile info is correct, so I'm at a loss as to what is causing it to return nothing.  I am assuming that the -host flag is used to denote the forwarder that the logs originated from, and that the -source is the full path of the logfile.  (Ex:  'D:\apache-tomcat-6.0.32\bin\server.log'.  I have tried it both escaped and not)  &lt;/P&gt;

&lt;P&gt;Has anyone else run into this issue?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2011 18:50:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Unable-to-filter-CLI-export/m-p/106601#M2454</guid>
      <dc:creator>emiller42</dc:creator>
      <dc:date>2011-11-08T18:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to filter CLI export</title>
      <link>https://community.splunk.com/t5/Reporting/Unable-to-filter-CLI-export/m-p/106602#M2455</link>
      <description>&lt;P&gt;Yeah, I'm seeing this as well on version 2.4.3. It turns out this is a known issue (SPL-45694) and it's currently being investigated.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2011 16:37:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Unable-to-filter-CLI-export/m-p/106602#M2455</guid>
      <dc:creator>alexiri</dc:creator>
      <dc:date>2011-12-15T16:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to filter CLI export</title>
      <link>https://community.splunk.com/t5/Reporting/Unable-to-filter-CLI-export/m-p/106603#M2456</link>
      <description>&lt;P&gt;I tested following commands with 4.3.3 release and both work fine:&lt;BR /&gt;
splunk export eventdata -index main -dir /temp/events.out -source 'C:\work\test\test.log'&lt;BR /&gt;
splunk export eventdata -index main -dir /temp/raven -host 'raven-PC'&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jul 2012 20:02:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Unable-to-filter-CLI-export/m-p/106603#M2456</guid>
      <dc:creator>xli_splunk</dc:creator>
      <dc:date>2012-07-06T20:02:15Z</dc:date>
    </item>
  </channel>
</rss>

