Deployment Architecture

Will CSV files produced by the outputcsv command be replicated by the search head cluster?

606866581
Path Finder

Hi all,

I currently have 1 search head running all my scheduled searches. Some of these searches use the outputcsv command to export Splunk results for use in other systems. Will these CSV files be replicated by the search head cluster? I won't be able to control which search head produces the CSV, so I need to know if Splunk deals with this or not.

I've searched through the documentation, but haven't found anything explicit. Any help would be greatly appreciated!

Thanks

1 Solution

606866581
Path Finder

http://docs.splunk.com/Documentation/Splunk/6.4.1/SearchReference/Outputcsv

Updates to $SPLUNK_HOME/var/run/*.csv using the outputcsv command are not replicated across the cluster.

This answered my question

View solution in original post

koshyk
Super Champion

outputlookup is better because
- As woodcock said, it is replicated to all SH members in a SHC
- You can control where the csv resides. Example if your app has a saved-search, it will ensure that the csv will reside within the app and NOT in $SPLUNK_HOME/var/run/ , thus providing more acl to the lookup

0 Karma

606866581
Path Finder

http://docs.splunk.com/Documentation/Splunk/6.4.1/SearchReference/Outputcsv

Updates to $SPLUNK_HOME/var/run/*.csv using the outputcsv command are not replicated across the cluster.

This answered my question

woodcock
Esteemed Legend

You can switch from outputcsv to outputlookup and use a KV Store instead and that should replicate everywhere.

606866581
Path Finder

Thanks Gregg, this is probably the best workaround we were able to come up with

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...