Deployment Architecture

Will CSV files produced by the outputcsv command be replicated by the search head cluster?

606866581
Path Finder

Hi all,

I currently have 1 search head running all my scheduled searches. Some of these searches use the outputcsv command to export Splunk results for use in other systems. Will these CSV files be replicated by the search head cluster? I won't be able to control which search head produces the CSV, so I need to know if Splunk deals with this or not.

I've searched through the documentation, but haven't found anything explicit. Any help would be greatly appreciated!

Thanks

1 Solution

606866581
Path Finder

http://docs.splunk.com/Documentation/Splunk/6.4.1/SearchReference/Outputcsv

Updates to $SPLUNK_HOME/var/run/*.csv using the outputcsv command are not replicated across the cluster.

This answered my question

View solution in original post

koshyk
Super Champion

outputlookup is better because
- As woodcock said, it is replicated to all SH members in a SHC
- You can control where the csv resides. Example if your app has a saved-search, it will ensure that the csv will reside within the app and NOT in $SPLUNK_HOME/var/run/ , thus providing more acl to the lookup

0 Karma

606866581
Path Finder

http://docs.splunk.com/Documentation/Splunk/6.4.1/SearchReference/Outputcsv

Updates to $SPLUNK_HOME/var/run/*.csv using the outputcsv command are not replicated across the cluster.

This answered my question

woodcock
Esteemed Legend

You can switch from outputcsv to outputlookup and use a KV Store instead and that should replicate everywhere.

606866581
Path Finder

Thanks Gregg, this is probably the best workaround we were able to come up with

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...