Outputcsv command will export the log to a csv file in var\run\splunk location. I have used only enterprise trial version of splunk and i want to know how will it be in real scenario where we have multiple indexers, searchheads etc. Where this file will be stored? Whether in the indexer or Searchhead or Deployment server .
Incase the file is located in an indexer or Search head , how can i access the file (inputcsv) from different indexer or searchhead instance.
I have a scenario where i have created a schedule search which will update the csv file. And i have dashboards created reading values from this csv file using inputcsv command. Right now it is working in Enterprise trial version (single splunk instance). In real scenario i want to know whether this csv file will be generated in a centralised location.
Are you planning to use Search Head pooling (may be using Shared NAS) and Will you be using a Separate JobServer instance for these saved searches or they will be scheduled on Search Heads only?