Hi at all,
I need to use SID as filename in an outputcsv command.
I reached to do this in a normal search
my_search | ... | addinfo | outputcsv [ search * | head 1 | addinfo | eval query="my_alert_".info_sid | fields query | format "" "" "" "" "" "" ] singlefile=1
and I have a file called "mysearch1234567890.12345.csv".
The problem is when I schedule this search in an alert because the output csv is "mysearchscheduleadmin.csv", in other words: running an alerts, instead SID I have the fixed string "scheduleadmin".
Anyone has an idea where to search solution or (best) has a solution to solve the problem?
Thank you in advance.
Just FYI, if you are using search head pooling or search head clustering then
outputcsv is not compatible, see reference doc http://docs.splunk.com/Documentation/Splunk/7.0.1/SearchReference/Outputcsv#Distributed_deployments