Reporting

How can I export search results as LEEF (Log Event Extended Format (LEEF) - IBM)

ryoji_solsys
Explorer

Splunk doesn't seem to have a supported option to export data as LEEF.

Could anyone please suggest any customized way to export data as LEEF ?

Thanks,
R

Tags (1)
0 Karma

jkat54
SplunkTrust
SplunkTrust

You can use eval statements like mvappend to create one field in LEEF format and then export to csv...

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...