Reporting

How can I extract aggregated data from a report in Splunk?

morariu94
New Member

Hello,

We receive web access logs in Splunk.

I created a report in Splunk that aggregates the data( web access logs) , information like total number of calls and total number of error calls per customer.

I saw that I can easily extract the data in JSON format from the report using the Splunk UI but I need to do this programmatically cause I need afterwards to send the file to a different place.

How can I achieve this?

Thank you,

Andrei

Labels (2)
0 Karma

Richfez
SplunkTrust
SplunkTrust

You can run regular searches directly from the cli.

https://docs.splunk.com/Documentation/Splunk/8.0.6/Admin/GethelpwiththeCLI

To run a saved search, you'll need to use | savedsearch, which means you have a pipe in there, which means if you are using Windows it might get tricky.  Linux has less problem with that issue.

Another option, possibly/probably better, is rest.

https://docs.splunk.com/Documentation/Splunk/8.0.6/Search/ExportdatausingRESTAPI

Again, linux this is easy, in windows you'll have to find "curl" somewhere.

 

Happy Splunking!

-Rich

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...