<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic export results to csv in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10553#M511</link>
    <description>&lt;P&gt;What's the easiest way to export Splunk search results to a CSV file that I can open in Excel? &lt;/P&gt;</description>
    <pubDate>Fri, 26 Mar 2010 03:10:33 GMT</pubDate>
    <dc:creator>Justin_Grant</dc:creator>
    <dc:date>2010-03-26T03:10:33Z</dc:date>
    <item>
      <title>export results to csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10553#M511</link>
      <description>&lt;P&gt;What's the easiest way to export Splunk search results to a CSV file that I can open in Excel? &lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2010 03:10:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10553#M511</guid>
      <dc:creator>Justin_Grant</dc:creator>
      <dc:date>2010-03-26T03:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: export results to csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10554#M512</link>
      <description>&lt;P&gt;If there are fewer than 10,000 lines to export, then "Actions&amp;gt;Export Results..." from the Search or Charting views, after a search has finished running. The menu item is not available on most other dashboards or views.&lt;/P&gt;

&lt;P&gt;I think that the "Action" menu is nearly invisible, so lots of people miss it.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2010 03:52:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10554#M512</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-03-26T03:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: export results to csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10555#M513</link>
      <description>&lt;P&gt;Alternatively, try the &lt;CODE&gt;outputcsv&lt;/CODE&gt; command like this:&lt;/P&gt;

&lt;P&gt;splunk &amp;gt; my super cool search | outputcsv mycsvfilename&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2010 04:29:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10555#M513</guid>
      <dc:creator>hulahoop</dc:creator>
      <dc:date>2010-03-26T04:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: export results to csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10556#M514</link>
      <description>&lt;P&gt;Both of these are good answers, but this one matches more closely what I was trying to do.  thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 27 Mar 2010 04:02:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10556#M514</guid>
      <dc:creator>Justin_Grant</dc:creator>
      <dc:date>2010-03-27T04:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: export results to csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10557#M515</link>
      <description>&lt;P&gt;This is also discussed here: &lt;A href="http://blogs.splunk.com/2009/08/07/help-i-cant-export-more-than-10000-events/" rel="nofollow"&gt;http://blogs.splunk.com/2009/08/07/help-i-cant-export-more-than-10000-events/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2010 22:07:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10557#M515</guid>
      <dc:creator>Dan</dc:creator>
      <dc:date>2010-04-21T22:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: export results to csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10558#M516</link>
      <description>&lt;P&gt;What version of Splunk are you running?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2010 22:07:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10558#M516</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-04-21T22:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: export results to csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10559#M517</link>
      <description>&lt;P&gt;+1 for 'I think that the "Action" menu is nearly invisible, so lots of people miss it.'!&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2012 00:39:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10559#M517</guid>
      <dc:creator>pkaeding</dc:creator>
      <dc:date>2012-04-11T00:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: export results to csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10560#M518</link>
      <description>&lt;P&gt;I could not find the "Action" menu in version 4.3.4.  There is an "-&amp;gt; Export" link just above list of matching events, though.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2013 15:39:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10560#M518</guid>
      <dc:creator>I_am_Jeff</dc:creator>
      <dc:date>2013-03-19T15:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: export results to csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10561#M519</link>
      <description>&lt;P&gt;This worked well.  Myself and a user that could not export a csv files to our desktop.  This dropped the file in our pool/var/run/splunk directory.  &lt;EM&gt;AND&lt;/EM&gt; the export link worked with this search.  (v 4.3.4)  I wonder if the initial problem is becauser our pooled search heads are behind a load balancer. . . ?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2013 15:40:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10561#M519</guid>
      <dc:creator>I_am_Jeff</dc:creator>
      <dc:date>2013-03-19T15:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: export results to csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10562#M520</link>
      <description>&lt;P&gt;I have been trying to export my search query's result to a csv file using 'outputcsv'. But no file is getting created. Not getting any error too.&lt;/P&gt;

&lt;P&gt;Here is my search query:&lt;/P&gt;

&lt;P&gt;| outputcsv trial.csv&lt;/P&gt;

&lt;P&gt;Please help.&lt;/P&gt;

&lt;P&gt;Are any settings required to be done to get the CSV output.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2015 11:11:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10562#M520</guid>
      <dc:creator>poojag</dc:creator>
      <dc:date>2015-03-17T11:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: export results to csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10563#M521</link>
      <description>&lt;P&gt;Today I had the Problem that a User wanted to export a CSV with over 13 million lines. &lt;BR /&gt;
He let the Search run in the background and it took over a day to  complete. &lt;BR /&gt;
Now he could not export his results and I did not want to run the search again with outputcsv.&lt;/P&gt;

&lt;P&gt;The solution I came up with was to look on the search head and find the result file for the search:&lt;BR /&gt;
/opt/splunk/var/run/splunk/dispatch//results.csv.gz&lt;/P&gt;

&lt;P&gt;I hope this helps everybody who has the same issue.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2015 15:30:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10563#M521</guid>
      <dc:creator>peter_krammer</dc:creator>
      <dc:date>2015-09-10T15:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: export results to csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10564#M522</link>
      <description>&lt;P&gt;you could have a look in splunkbase at the TA-XLS which allows in version 0.1 to convert the .csv generated by outputcsv to a Excelsheet and sendfile for sending it as a email attachment. The new version 0.2 has a outputcsv command that directly generates a .xls and allows for sending it via email. (i have trouble uploading the new version right now but in a day or so it should be there).&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2016 09:43:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10564#M522</guid>
      <dc:creator>dominiquevocat</dc:creator>
      <dc:date>2016-01-13T09:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: export results to csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10565#M523</link>
      <description>&lt;P&gt;Append "| sort Sourcetype | outputcsv output.csv" to your search.&lt;/P&gt;

&lt;P&gt;After the query runs, you should be able to go to $SPLUNK_HOME/ var/run/splunk/csv directory and see output.csv &lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2017 20:55:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/10565#M523</guid>
      <dc:creator>kalmira</dc:creator>
      <dc:date>2017-02-07T20:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: export results to csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/573035#M199733</link>
      <description>&lt;P&gt;Where is the default location of CSV output file defined in search string on Windows Server 2016?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Oct 2021 20:54:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/export-results-to-csv/m-p/573035#M199733</guid>
      <dc:creator>bergen288</dc:creator>
      <dc:date>2021-10-29T20:54:59Z</dc:date>
    </item>
  </channel>
</rss>

