Getting Data In

How to export real raw events from Splunk?

orion44
Communicator

Other answers imply that | table _raw | outputcsv is the method to export raw events from Splunk. However a csv file is not raw events as it, by design, is structured data.

I can export real raw events from the GUI via Search > Export > Format: Raw Events > Done.

How can this be done programmatically?

Tags (1)
0 Karma
1 Solution

orion44
Communicator

Solution: Use Splunk CLI to export the raw data.

splunk search "index=data earliest=-1h@h latest=@h" -output rawdata -maxout 200000 > "F:\Splunk Export\raw.txt"

View solution in original post

orion44
Communicator

Solution: Use Splunk CLI to export the raw data.

splunk search "index=data earliest=-1h@h latest=@h" -output rawdata -maxout 200000 > "F:\Splunk Export\raw.txt"

chrisyounger
SplunkTrust
SplunkTrust

I would argue that a CSV file with only one column in it (_raw) is not really structured data, becuase it doesn't even have any commas in it (unless they are in the raw data)...

I think this would be your best option.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...