Reporting

How can I extract aggregated data from a report in Splunk?

morariu94
New Member

Hello,

We receive web access logs in Splunk.

I created a report in Splunk that aggregates the data( web access logs) , information like total number of calls and total number of error calls per customer.

I saw that I can easily extract the data in JSON format from the report using the Splunk UI but I need to do this programmatically cause I need afterwards to send the file to a different place.

How can I achieve this?

Thank you,

Andrei

Labels (2)
0 Karma

Richfez
SplunkTrust
SplunkTrust

You can run regular searches directly from the cli.

https://docs.splunk.com/Documentation/Splunk/8.0.6/Admin/GethelpwiththeCLI

To run a saved search, you'll need to use | savedsearch, which means you have a pipe in there, which means if you are using Windows it might get tricky.  Linux has less problem with that issue.

Another option, possibly/probably better, is rest.

https://docs.splunk.com/Documentation/Splunk/8.0.6/Search/ExportdatausingRESTAPI

Again, linux this is easy, in windows you'll have to find "curl" somewhere.

 

Happy Splunking!

-Rich

0 Karma
Get Updates on the Splunk Community!

Happy CX Day to our Community Superheroes!

Happy 10th Birthday CX Day!What is CX Day? It’s a global celebration recognizing innovation and success in the ...

Check out This Month’s Brand new Splunk Lantern Articles

Splunk Lantern is a customer success center providing advice from Splunk experts on valuable data insights, ...

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...