Reporting

How to export logs from Splunk with host, source and sourcetype fields

jackson_storm
Explorer

Hello. I have a questions.

How to export logs from Splunk Enterprise with "host", "source" and "sourcetype" fields ?
And how to import these logs into other Splunk Enterprise instance correctly ?

I'm trying to export Windows logs from my current Splunk instance and save it for future usage or upload into other Splunk.
Using "Export" button i can only export raw logs without necessary for me fields("host", "source" and "sourcetype")

Good example is ButterCup Games training logs in Splunk documentation. I need to get something like this.

splunker12er
Motivator

How to export logs from Splunk Enterprise with "host", "source" and "sourcetype" fields ?

<yoursearch> |  table host, source, sourcetype, _raw

Once results are displayed click export to download logs.

How to upload into other Splunk.? (I use CLI command)

splunk add monitor c:\xxxx.log -index yourindexname -source yoursourcename -sourcetype yoursourcetypename -hostname yourhostname
0 Karma

jackson_storm
Explorer

What format should i use ?
CSV, XML or JSON ?
Export as raw data is not supported

0 Karma
Get Updates on the Splunk Community!

Splunk Education - Fast Start Program!

Welcome to Splunk Education! Splunk training programs are designed to enable you to get started quickly and ...

Five Subtly Different Ways of Adding Manual Instrumentation in Java

You can find the code of this example on GitHub here. Please feel free to star the repository to keep in ...

New Splunk APM Enhancements Help Troubleshoot Your MySQL and NoSQL Databases Faster

Splunk Observability has two new enhancements to make it quicker and easier to troubleshoot slow or frequently ...