Deployment Architecture

Will CSV files produced by the outputcsv command be replicated by the search head cluster?

606866581
Path Finder

Hi all,

I currently have 1 search head running all my scheduled searches. Some of these searches use the outputcsv command to export Splunk results for use in other systems. Will these CSV files be replicated by the search head cluster? I won't be able to control which search head produces the CSV, so I need to know if Splunk deals with this or not.

I've searched through the documentation, but haven't found anything explicit. Any help would be greatly appreciated!

Thanks

1 Solution

606866581
Path Finder

http://docs.splunk.com/Documentation/Splunk/6.4.1/SearchReference/Outputcsv

Updates to $SPLUNK_HOME/var/run/*.csv using the outputcsv command are not replicated across the cluster.

This answered my question

View solution in original post

koshyk
Super Champion

outputlookup is better because
- As woodcock said, it is replicated to all SH members in a SHC
- You can control where the csv resides. Example if your app has a saved-search, it will ensure that the csv will reside within the app and NOT in $SPLUNK_HOME/var/run/ , thus providing more acl to the lookup

0 Karma

606866581
Path Finder

http://docs.splunk.com/Documentation/Splunk/6.4.1/SearchReference/Outputcsv

Updates to $SPLUNK_HOME/var/run/*.csv using the outputcsv command are not replicated across the cluster.

This answered my question

woodcock
Esteemed Legend

You can switch from outputcsv to outputlookup and use a KV Store instead and that should replicate everywhere.

606866581
Path Finder

Thanks Gregg, this is probably the best workaround we were able to come up with

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...