I have a pretty basic query which generates a large (several hundred by several hundred) table.
host=XX OR host=YY print evtid="10" splunk_server="ami" | counttable evtuser, Printer_Name
I need to export this resulting table to a CSV. This function is apparently known to be broken based on some of the other answers I've seen. I'm only receiving the first column of output. Is there a ready way to do what I need?
So can't you just run
host=XX OR host=YY print evtid="10" splunk_server="ami" | counttable evtuser, Printer_Name | outputcsv myfile
Then the results are written to: '$SPLUNK_HOME/var/run/splunk/myfile.csv'
So can't you just run
host=XX OR host=YY print evtid="10" splunk_server="ami" | counttable evtuser, Printer_Name | outputcsv myfile
Then the results are written to: '$SPLUNK_HOME/var/run/splunk/myfile.csv'
Never used that command before, so this command aye?
http://docs.splunk.com/Documentation/Splunk/4.3.3/SearchReference/Contingency
@dmaislin_splunk - I'm rendering a count table in Splunk. I want to save this table to my local drive.
Did you mean outputcsv
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Outputcsv