Reporting

How do I export the search results for multiple searches to a single CSV file?

nbharadwaj
Path Finder

I need to run many searches and consolidate all the results. Each search looks like this

.......| stats count avg(field1) avg(field2)

So the output columns are always the same, and each search will only generate one row.

How can I send the output to one single CSV file? Is there a way to append to an existing CSV file?

I can go via the Web UI or via CLI- either way is fine. Thanks!

Tags (3)
0 Karma

Stephen_Sorkin
Splunk Employee
Splunk Employee

The most straightforward way is to use append:

... | stats count avg(field1) avg(field2) | append [search ... | stats count avg(field1) avg(field2)] | append [search ...] | ...

However, this isn't necessarily the most efficient.

Assuming that your initial search part is very simple, you can do something like:

(foo=A ...) OR (foo=B ...) OR (foo=C ...) | stats count avg(field1) avg(field2) by foo | fields - foo

Now, you may not have a field that cleanly splits the events. In that case you could use eval to synthesize one:

(<search A>) OR (<search B>) OR (<search C>) | eval foo = case(searchmatch("<search A>"), "A", ...) |  stats count avg(field1) avg(field2) by foo | fields - foo
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...