Getting Data In

Looking for alternatives to outputcsv in a Cloud deployment

tomapatan
Communicator

Hi,

Can someone recommend a way to save the results of a Splunk search locally or to shared drive? We`re using a hybrid deployment (Cloud and Enterprise), but the data we require is available in Cloud only.

Many thanks,

Toma

Labels (1)
0 Karma
1 Solution

Gr0und_Z3r0
Contributor

Hi @tomapatan 

You can use the REST API services of Splunk to export the data as CSV.
https://docs.splunk.com/Documentation/Splunk/latest/Search/ExportdatausingRESTAPI

~ If the reply helps, a Karma upvote would be appreciated.

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

With Cloud you don't have local access to the machines at the OS level and can't manipulate local files (and won't be able to push any apps that try to do so, they will fail vetting). So your only option is as @Gr0und_Z3r0 pointed out to use API from remote to spawn a search and then retrieve results.

Depending on the size of your output you could also try to send results via email action.

0 Karma

Gr0und_Z3r0
Contributor

Hi @tomapatan 

You can use the REST API services of Splunk to export the data as CSV.
https://docs.splunk.com/Documentation/Splunk/latest/Search/ExportdatausingRESTAPI

~ If the reply helps, a Karma upvote would be appreciated.

Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...