Reporting

How can I extract aggregated data from a report in Splunk?

morariu94
New Member

Hello,

We receive web access logs in Splunk.

I created a report in Splunk that aggregates the data( web access logs) , information like total number of calls and total number of error calls per customer.

I saw that I can easily extract the data in JSON format from the report using the Splunk UI but I need to do this programmatically cause I need afterwards to send the file to a different place.

How can I achieve this?

Thank you,

Andrei

Labels (2)
0 Karma

Richfez
SplunkTrust
SplunkTrust

You can run regular searches directly from the cli.

https://docs.splunk.com/Documentation/Splunk/8.0.6/Admin/GethelpwiththeCLI

To run a saved search, you'll need to use | savedsearch, which means you have a pipe in there, which means if you are using Windows it might get tricky.  Linux has less problem with that issue.

Another option, possibly/probably better, is rest.

https://docs.splunk.com/Documentation/Splunk/8.0.6/Search/ExportdatausingRESTAPI

Again, linux this is easy, in windows you'll have to find "curl" somewhere.

 

Happy Splunking!

-Rich

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!