Other Usage

How to Properly Read results.csv.gz From Dispatch

morethanyell
Builder

After a successful saved-search run, the results can be found on the directory `$SPLUNK_HOME/var/run/splunk/dispatch/scheduler__...` 

We know that the result of the search is named `results.csv.gz` 

How do we read this in the OS level apps? Untarring it using `tar -xzvf` does not work.

 

Thanks

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

It's not a tarball so tar won't help.  It's just a CSV file compressed with gzip.  You should be able to view it using gunzip -c results.csv.gz | more

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

It's not a tarball so tar won't help.  It's just a CSV file compressed with gzip.  You should be able to view it using gunzip -c results.csv.gz | more

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...