I have a pretty basic query which generates a large (several hundred by several hundred) table.
host=XX OR host=YY print evtid="10" splunk_server="ami" | counttable evtuser, Printer_Name
I need to export this resulting table to a CSV. This function is apparently known to be broken based on some of the other answers I've seen. I'm only receiving the first column of output. Is there a ready way to do what I need?
So can't you just run
host=XX OR host=YY print evtid="10" splunk_server="ami" | counttable evtuser, Printer_Name | outputcsv myfile
Then the results are written to: '$SPLUNK_HOME/var/run/splunk/myfile.csv'