Reporting

Help in Outputcsv command

jagadish85
Path Finder

Outputcsv command will export the log to a csv file in var\run\splunk location. I have used only enterprise trial version of splunk and i want to know how will it be in real scenario where we have multiple indexers, searchheads etc. Where this file will be stored? Whether in the indexer or Searchhead or Deployment server .

Incase the file is located in an indexer or Search head , how can i access the file (inputcsv) from different indexer or searchhead instance.

I have a scenario where i have created a schedule search which will update the csv file. And i have dashboards created reading values from this csv file using inputcsv command. Right now it is working in Enterprise trial version (single splunk instance). In real scenario i want to know whether this csv file will be generated in a centralised location.

Thanks
Jagadish

Tags (1)
0 Karma
1 Solution

strive
Influencer

The CSV file will be created in the location (node/machine) where the search runs.

View solution in original post

jagadish85
Path Finder

Thanks for your response.

Yes I am planning to use Search Head Pooling and savedsearch will be scheduled on Search Heads

0 Karma

somesoni2
Revered Legend

Are you planning to use Search Head pooling (may be using Shared NAS) and Will you be using a Separate JobServer instance for these saved searches or they will be scheduled on Search Heads only?

0 Karma

strive
Influencer

Where are you planning to keep your Saved Search which creates the CSV file and the search which is used for dashboard?

0 Karma

strive
Influencer

The CSV file will be created in the location (node/machine) where the search runs.

jagadish85
Path Finder

Thanks Strive

0 Karma

strive
Influencer

If you want to write CSV file to same app's lookups directory then try using outputlookup command

http://docs.splunk.com/Documentation/Splunk/6.1.2/SearchReference/Outputlookup

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...

Index This | What is feather-light but cannot be held long?

May 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

.conf26 Registration is Live: Secure Your Early Bird Pass Now

  Lock in Your Spot: Registration Open for .conf26 in Denver Hello Splunkers, I have exciting news! Your ...