Reporting

How to export search results - csv output to a sharepoint location

p_basanth
New Member

Hi, I have created a saved search and scheduled it to run weekly basis.
Any pointers on how to export the results in a csv and send it to sharepoint location.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could write an alert script that connects to sharepoint and sends the results, and have that script triggered by your weekly scheduled report.

somesoni2
Revered Legend

Agree with @martin_mueller. Have your scheduled search run an "exportcsv" command in the end and the exported csv file will be created in $SPLUNK_HOME/var/run/splunk folder. Later configure an alert executing script to either push directly to sharepoint (using some API) or copy it to sharepoint's shared location.

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...