Getting Data In

Exporting search results automatically

logicasrl
Explorer

Simple question: how is it possible to export a search result in a CSV file in a scheduled manner (automatically) in Windows? The problem is the "automatically" term: from web interface, interactively, as a matter of fact there is NO problem... Splunk Version is 4.1.2. Thank you very much, Luca

Tags (3)
1 Solution

bwooden
Splunk Employee
Splunk Employee

First, craft the search and make sure it returns the desired results:

sourcetype=syslog

After confirming, pipe that to outputcsv:

sourcetype=syslog | outputcsv results.csv

Finally, drop down the Actions menu and select Save search...
After filling in the desired name, time range, etc. check the Schedule this search checkbox and select a recurrence before saving.

Your file should automatically be generated here at your scheduled interval:

$SPLUNK_HOME/var/run/splunk/results.csv

View solution in original post

bwooden
Splunk Employee
Splunk Employee

First, craft the search and make sure it returns the desired results:

sourcetype=syslog

After confirming, pipe that to outputcsv:

sourcetype=syslog | outputcsv results.csv

Finally, drop down the Actions menu and select Save search...
After filling in the desired name, time range, etc. check the Schedule this search checkbox and select a recurrence before saving.

Your file should automatically be generated here at your scheduled interval:

$SPLUNK_HOME/var/run/splunk/results.csv

Lowell
Super Champion

Here's an question showing a few different ways to add a timestamp to an output file: http://answers.splunk.com/answers/39974/variable-file-name-in-outputcsv

0 Karma

logicasrl
Explorer

Another request about the subject:

which one could be a viable solution if there was the necessity of inserting a "timestamp" into the name of the "result.csv" file above?

Thanks again,

Luca

0 Karma

logicasrl
Explorer

Perfect: it works like a charm 🙂
I've read the documentation, but I was not able to find such an information.
Thank you very much,
Luca

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...