Getting Data In

CLI: Linux vs. Windows

NK_1
Path Finder

Using the CLI, if I do

splunk search hoursago=1

I see output under a Linux Splunk installation, but not under a Windows Splunk installation.

Where does the output from the Windows installation go?

Tags (4)
1 Solution

gekoner
Communicator

I assume you are running Splunk 4.2.2 or higher and this is on a Windows 2008 server. You will need to run the command prompt with elevated privileges (Run as administrator). Then it should echo out to the same command screen.
If you don't it opens a new window, and if the results return quickly you might not even see the new command window popup.

View solution in original post

gekoner
Communicator

I assume you are running Splunk 4.2.2 or higher and this is on a Windows 2008 server. You will need to run the command prompt with elevated privileges (Run as administrator). Then it should echo out to the same command screen.
If you don't it opens a new window, and if the results return quickly you might not even see the new command window popup.

echalex
Builder

Thank you for the answer, gekoner. I hade the same kind of problem under Windows 7. Any splunk command, such as splunk status would only quickly flicker another terminal window. Opening cmd with "run as administrator" solved this issue.

0 Karma

NK_1
Path Finder

splunk search "daysago=1 AccountName" > c:\accounts.log

Tried this on Splunk 4.2.3 under Windows 7 Enterprise, and that was it (i.e. need to run the command shell as Admin). Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Improve Delivery Assurance with S2S ACK for Edge Processor

Edge Processor helps Splunk customers process data closer to the source: filtering, transforming, masking, and ...

.conf26 Platform Sessions: Turn Machine Data into Agentic Action

As autonomous agents and multi-cloud architectures reshape modern IT, data platforms have to do far more than ...

Introducing the Launch of Edge Processor in Hybrid Mode!

Modernize Data Ingestion Without Starting Over  For years, organizations have relied on Splunk's proven ...