Reporting

How to export search results - csv output to a sharepoint location

p_basanth
New Member

Hi, I have created a saved search and scheduled it to run weekly basis.
Any pointers on how to export the results in a csv and send it to sharepoint location.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could write an alert script that connects to sharepoint and sends the results, and have that script triggered by your weekly scheduled report.

somesoni2
Revered Legend

Agree with @martin_mueller. Have your scheduled search run an "exportcsv" command in the end and the exported csv file will be created in $SPLUNK_HOME/var/run/splunk folder. Later configure an alert executing script to either push directly to sharepoint (using some API) or copy it to sharepoint's shared location.

Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...