Reporting

How can I extract aggregated data from a report in Splunk?

morariu94
New Member

Hello,

We receive web access logs in Splunk.

I created a report in Splunk that aggregates the data( web access logs) , information like total number of calls and total number of error calls per customer.

I saw that I can easily extract the data in JSON format from the report using the Splunk UI but I need to do this programmatically cause I need afterwards to send the file to a different place.

How can I achieve this?

Thank you,

Andrei

Labels (1)
0 Karma

Richfez
SplunkTrust
SplunkTrust

You can run regular searches directly from the cli.

https://docs.splunk.com/Documentation/Splunk/8.0.6/Admin/GethelpwiththeCLI

To run a saved search, you'll need to use | savedsearch, which means you have a pipe in there, which means if you are using Windows it might get tricky.  Linux has less problem with that issue.

Another option, possibly/probably better, is rest.

https://docs.splunk.com/Documentation/Splunk/8.0.6/Search/ExportdatausingRESTAPI

Again, linux this is easy, in windows you'll have to find "curl" somewhere.

 

Happy Splunking!

-Rich

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...