Reporting

How to export logs from Splunk with host, source and sourcetype fields

jackson_storm
Explorer

Hello. I have a questions.

How to export logs from Splunk Enterprise with "host", "source" and "sourcetype" fields ?
And how to import these logs into other Splunk Enterprise instance correctly ?

I'm trying to export Windows logs from my current Splunk instance and save it for future usage or upload into other Splunk.
Using "Export" button i can only export raw logs without necessary for me fields("host", "source" and "sourcetype")

Good example is ButterCup Games training logs in Splunk documentation. I need to get something like this.

splunker12er
Motivator

How to export logs from Splunk Enterprise with "host", "source" and "sourcetype" fields ?

<yoursearch> |  table host, source, sourcetype, _raw

Once results are displayed click export to download logs.

How to upload into other Splunk.? (I use CLI command)

splunk add monitor c:\xxxx.log -index yourindexname -source yoursourcename -sourcetype yoursourcetypename -hostname yourhostname
0 Karma

jackson_storm
Explorer

What format should i use ?
CSV, XML or JSON ?
Export as raw data is not supported

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...