@mbadar,
You should add "|outputcsv <filename>
" to the end of your search syntax.
For example,
ip=10.1.1.* | outputcsv myresults.csv
Here is the docs for this...
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Outputcsv
I find this quite good in automating the output of this data.
Regards,
MHibbin
@mbadar,
You should add "|outputcsv <filename>
" to the end of your search syntax.
For example,
ip=10.1.1.* | outputcsv myresults.csv
Here is the docs for this...
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Outputcsv
I find this quite good in automating the output of this data.
Regards,
MHibbin