<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File not found on export in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/File-not-found-on-export/m-p/75377#M181350</link>
    <description>&lt;P&gt;We're searching an IP address. Searche results for other IP addresses can be exported, but for some reason this one shows the error. The data in the results events look fine.&lt;/P&gt;

&lt;P&gt;We are on v. 4.3.3 in a distributed environment.&lt;/P&gt;</description>
    <pubDate>Mon, 01 Oct 2012 18:23:29 GMT</pubDate>
    <dc:creator>gmonroe</dc:creator>
    <dc:date>2012-10-01T18:23:29Z</dc:date>
    <item>
      <title>File not found on export</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-not-found-on-export/m-p/75373#M181346</link>
      <description>&lt;P&gt;When trying to export search results, I'm getting an error that reads "File not found. Firefox can't find the file at http...".&lt;/P&gt;

&lt;P&gt;What would cause this and what are possible fixes for it?&lt;/P&gt;</description>
      <pubDate>Sat, 29 Sep 2012 00:03:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-not-found-on-export/m-p/75373#M181346</guid>
      <dc:creator>gmonroe</dc:creator>
      <dc:date>2012-09-29T00:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: File not found on export</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-not-found-on-export/m-p/75374#M181347</link>
      <description>&lt;P&gt;Sounds like access privileges? Are you running as admin or equiv, or has your user id sufficient permissions? If you have CLI access perhaps also check out the access controls in.../metadata filename is default.meta. Export may be set to Admin as the default.&lt;BR /&gt;
Best wishes.&lt;BR /&gt;
D&lt;/P&gt;</description>
      <pubDate>Sun, 30 Sep 2012 13:19:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-not-found-on-export/m-p/75374#M181347</guid>
      <dc:creator>DaveSavage</dc:creator>
      <dc:date>2012-09-30T13:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: File not found on export</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-not-found-on-export/m-p/75375#M181348</link>
      <description>&lt;P&gt;Dave, thanks for responding. I don't think it's a permissions issue. I, and other users, are able to export other search results, but this one in particular returns the error. In the meantime, I will do as you suggested and check the access controls and all permissions.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 06:41:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-not-found-on-export/m-p/75375#M181348</guid>
      <dc:creator>gmonroe</dc:creator>
      <dc:date>2012-10-01T06:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: File not found on export</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-not-found-on-export/m-p/75376#M181349</link>
      <description>&lt;P&gt;Could you post the search? Also what version are you running? Is this a distributed environment?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 08:32:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-not-found-on-export/m-p/75376#M181349</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-10-01T08:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: File not found on export</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-not-found-on-export/m-p/75377#M181350</link>
      <description>&lt;P&gt;We're searching an IP address. Searche results for other IP addresses can be exported, but for some reason this one shows the error. The data in the results events look fine.&lt;/P&gt;

&lt;P&gt;We are on v. 4.3.3 in a distributed environment.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 18:23:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-not-found-on-export/m-p/75377#M181350</guid>
      <dc:creator>gmonroe</dc:creator>
      <dc:date>2012-10-01T18:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: File not found on export</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-not-found-on-export/m-p/75378#M181351</link>
      <description>&lt;P&gt;We are havnig the same problem - even if Admin runs the same query. In fact, it seems to depend on how many rows are returned. If we return many rows, then the export returns this error more frequently. We have found that if we wait a minute or two, then we can click on the "Try Again" link in the message and it sometimes works. Also, if we cut and paste the link to the exported data, it starts to export. The queries that tend to do this also have many columns (80?).&lt;/P&gt;

&lt;P&gt;We are running 4.3.1, build 119532 on our local search head in a globally distributed env.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2012 13:55:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-not-found-on-export/m-p/75378#M181351</guid>
      <dc:creator>reed_kelly</dc:creator>
      <dc:date>2012-10-03T13:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: File not found on export</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-not-found-on-export/m-p/75379#M181352</link>
      <description>&lt;P&gt;When you extend your searchstring with &lt;BR /&gt;
     | table _raw | outputcsv output.csv&lt;BR /&gt;
you can find you exprted results in $SPLUNK_HOME/var/run/splunk. &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:52:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-not-found-on-export/m-p/75379#M181352</guid>
      <dc:creator>Moritz</dc:creator>
      <dc:date>2020-09-28T15:52:46Z</dc:date>
    </item>
  </channel>
</rss>

