Dashboards & Visualizations

Export Splunk results to an XML output?

Dark_Ichigo
Builder

Is there a way to export Splunk results from a Report, chart...etc to an XML based output?

I noticed that someone was trying to accomplish this but there wasn't enough information on the approach of how he was achieving this: http://splunk-base.splunk.com/answers/13739/output-xml-via-a-custom-search-command

0 Karma

bharathkumarnec
Contributor

Hi All,

Looks like this can be done via splunkweb,CLI,REST API,SDK's & Dump commands. PFB link for more information:

http://docs.splunk.com/Documentation/Splunk/6.6.0/Search/Exportsearchresults

0 Karma

Dark_Ichigo
Builder

Ok, I have found out that there is an automated feature in splunk that allows you to export your results at a Click of a Button ( Basically the Action Menu 😛 ).

I also discovered with Damien's help that I can play around with it using the REST API, via a Python Script so that I may Modify the XML to the way I want it to look.

But Im not exactly %100 sure that if you can Modify the OutPut XML to your requirements?, can this be done?, has anyone ever tried this?, again the only person I found that actually engaged in performing this the way I want to is MW with his question: http://splunk-base.splunk.com/answers/13739/output-xml-via-a-custom-search-command

0 Karma

Damien_Dallimor
Ultra Champion

I'm not sure about the feasibility of modifying the schema of the response XML.
But as you mention, from your python script, you could use the Splunk Python SDK and then transform the original result XML from the REST call into an XML format to suit your specific requirements.

0 Karma

Damien_Dallimor
Ultra Champion

Not an export as such, but you could invoke the search using the REST api.

0 Karma

Dark_Ichigo
Builder

So I can extract the events and arrange them by there field names using a python script to do so?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...