Getting Data In

Exporting search results automatically

logicasrl
Explorer

Simple question: how is it possible to export a search result in a CSV file in a scheduled manner (automatically) in Windows? The problem is the "automatically" term: from web interface, interactively, as a matter of fact there is NO problem... Splunk Version is 4.1.2. Thank you very much, Luca

Tags (3)
1 Solution

bwooden
Splunk Employee
Splunk Employee

First, craft the search and make sure it returns the desired results:

sourcetype=syslog

After confirming, pipe that to outputcsv:

sourcetype=syslog | outputcsv results.csv

Finally, drop down the Actions menu and select Save search...
After filling in the desired name, time range, etc. check the Schedule this search checkbox and select a recurrence before saving.

Your file should automatically be generated here at your scheduled interval:

$SPLUNK_HOME/var/run/splunk/results.csv

View solution in original post

bwooden
Splunk Employee
Splunk Employee

First, craft the search and make sure it returns the desired results:

sourcetype=syslog

After confirming, pipe that to outputcsv:

sourcetype=syslog | outputcsv results.csv

Finally, drop down the Actions menu and select Save search...
After filling in the desired name, time range, etc. check the Schedule this search checkbox and select a recurrence before saving.

Your file should automatically be generated here at your scheduled interval:

$SPLUNK_HOME/var/run/splunk/results.csv

Lowell
Super Champion

Here's an question showing a few different ways to add a timestamp to an output file: http://answers.splunk.com/answers/39974/variable-file-name-in-outputcsv

0 Karma

logicasrl
Explorer

Another request about the subject:

which one could be a viable solution if there was the necessity of inserting a "timestamp" into the name of the "result.csv" file above?

Thanks again,

Luca

0 Karma

logicasrl
Explorer

Perfect: it works like a charm 🙂
I've read the documentation, but I was not able to find such an information.
Thank you very much,
Luca

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...