Getting Data In

Exporting search results automatically

logicasrl
Explorer

Simple question: how is it possible to export a search result in a CSV file in a scheduled manner (automatically) in Windows? The problem is the "automatically" term: from web interface, interactively, as a matter of fact there is NO problem... Splunk Version is 4.1.2. Thank you very much, Luca

Tags (3)
1 Solution

bwooden
Splunk Employee
Splunk Employee

First, craft the search and make sure it returns the desired results:

sourcetype=syslog

After confirming, pipe that to outputcsv:

sourcetype=syslog | outputcsv results.csv

Finally, drop down the Actions menu and select Save search...
After filling in the desired name, time range, etc. check the Schedule this search checkbox and select a recurrence before saving.

Your file should automatically be generated here at your scheduled interval:

$SPLUNK_HOME/var/run/splunk/results.csv

View solution in original post

bwooden
Splunk Employee
Splunk Employee

First, craft the search and make sure it returns the desired results:

sourcetype=syslog

After confirming, pipe that to outputcsv:

sourcetype=syslog | outputcsv results.csv

Finally, drop down the Actions menu and select Save search...
After filling in the desired name, time range, etc. check the Schedule this search checkbox and select a recurrence before saving.

Your file should automatically be generated here at your scheduled interval:

$SPLUNK_HOME/var/run/splunk/results.csv

Lowell
Super Champion

Here's an question showing a few different ways to add a timestamp to an output file: http://answers.splunk.com/answers/39974/variable-file-name-in-outputcsv

0 Karma

logicasrl
Explorer

Another request about the subject:

which one could be a viable solution if there was the necessity of inserting a "timestamp" into the name of the "result.csv" file above?

Thanks again,

Luca

0 Karma

logicasrl
Explorer

Perfect: it works like a charm 🙂
I've read the documentation, but I was not able to find such an information.
Thank you very much,
Luca

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...