I have noticed a difference in format between the csv files generated by Splunk when e-mail the results or saving them using the outputcsv function.
If I export the results to e-mail the multiline Windows events are processed as a single field with \n for new lines.
When I export the results into a field the multilines are preserved and I cannot use the csv fields in an excel sheet since Excel sees them as multiple lines.
First of all did anyone notice this as well and second (even more important 🙂 ) how can i change this so that the outputcsv function works the same as the e-mail function?
Second question, could anyone tell me if it is possible to change the names of the csv files stored by the outputcsv function?