<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: curl fields order on export csv in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/curl-fields-order-on-export-csv/m-p/193608#M55757</link>
    <description>&lt;P&gt;Oh, yes! So the answer is that the cosmetics of the search, in this case the field ordering, happen on the search UI. So it turns out the command line search doesn't do this formatting and therefore the field order is disregarded.&lt;/P&gt;

&lt;P&gt;I highlighted that this is misleading. There is no warning to the user that they are attempting to use a command (fields, table) which will not have expected behavior.&lt;/P&gt;

&lt;P&gt;I have case 190546 open for a feature request to "So that the order when using output=csv and the default xml output mode are consistent."&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jul 2015 13:23:53 GMT</pubDate>
    <dc:creator>sloshburch</dc:creator>
    <dc:date>2015-07-07T13:23:53Z</dc:date>
    <item>
      <title>curl fields order on export csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/curl-fields-order-on-export-csv/m-p/193606#M55755</link>
      <description>&lt;P&gt;When running a curl for &lt;CODE&gt;servicesNS/-/-/search/jobs/export -d search="savedsearch temp" -d output_mode=csv&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I see that the fields do not output in the order as defined by the underlying search.&lt;/P&gt;

&lt;P&gt;Conversely, when running the same curl, but removing the &lt;CODE&gt;-d output_mode=csv&lt;/CODE&gt;, I see the fields output in the correct order.&lt;/P&gt;

&lt;P&gt;Before opening a bug, I figured I'd check with the community.  Has anyone seen this before? Known issue or by design?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jun 2014 21:59:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/curl-fields-order-on-export-csv/m-p/193606#M55755</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2014-06-09T21:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: curl fields order on export csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/curl-fields-order-on-export-csv/m-p/193607#M55756</link>
      <description>&lt;P&gt;@SloshBurch, did you get an answer from Splunk on this?  I'm seeing a similar behavior.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2015 12:21:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/curl-fields-order-on-export-csv/m-p/193607#M55756</guid>
      <dc:creator>cphair</dc:creator>
      <dc:date>2015-07-07T12:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: curl fields order on export csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/curl-fields-order-on-export-csv/m-p/193608#M55757</link>
      <description>&lt;P&gt;Oh, yes! So the answer is that the cosmetics of the search, in this case the field ordering, happen on the search UI. So it turns out the command line search doesn't do this formatting and therefore the field order is disregarded.&lt;/P&gt;

&lt;P&gt;I highlighted that this is misleading. There is no warning to the user that they are attempting to use a command (fields, table) which will not have expected behavior.&lt;/P&gt;

&lt;P&gt;I have case 190546 open for a feature request to "So that the order when using output=csv and the default xml output mode are consistent."&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2015 13:23:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/curl-fields-order-on-export-csv/m-p/193608#M55757</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2015-07-07T13:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: curl fields order on export csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/curl-fields-order-on-export-csv/m-p/193609#M55758</link>
      <description>&lt;P&gt;Good to know.  Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2015 13:31:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/curl-fields-order-on-export-csv/m-p/193609#M55758</guid>
      <dc:creator>cphair</dc:creator>
      <dc:date>2015-07-07T13:31:37Z</dc:date>
    </item>
  </channel>
</rss>

