Deployment Architecture

Will CSV files produced by the outputcsv command be replicated by the search head cluster?

606866581
Path Finder

Hi all,

I currently have 1 search head running all my scheduled searches. Some of these searches use the outputcsv command to export Splunk results for use in other systems. Will these CSV files be replicated by the search head cluster? I won't be able to control which search head produces the CSV, so I need to know if Splunk deals with this or not.

I've searched through the documentation, but haven't found anything explicit. Any help would be greatly appreciated!

Thanks

1 Solution

606866581
Path Finder

http://docs.splunk.com/Documentation/Splunk/6.4.1/SearchReference/Outputcsv

Updates to $SPLUNK_HOME/var/run/*.csv using the outputcsv command are not replicated across the cluster.

This answered my question

View solution in original post

koshyk
Super Champion

outputlookup is better because
- As woodcock said, it is replicated to all SH members in a SHC
- You can control where the csv resides. Example if your app has a saved-search, it will ensure that the csv will reside within the app and NOT in $SPLUNK_HOME/var/run/ , thus providing more acl to the lookup

0 Karma

606866581
Path Finder

http://docs.splunk.com/Documentation/Splunk/6.4.1/SearchReference/Outputcsv

Updates to $SPLUNK_HOME/var/run/*.csv using the outputcsv command are not replicated across the cluster.

This answered my question

woodcock
Esteemed Legend

You can switch from outputcsv to outputlookup and use a KV Store instead and that should replicate everywhere.

606866581
Path Finder

Thanks Gregg, this is probably the best workaround we were able to come up with

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...