Assuming not SHC, create a cron job in the OS of the Search Head that runs every X-minutes looking in the dispatch directory for files named XFERME_<destination>_<real_name_starts_here>.csv which does sftp then rm. Create them using |outputcsv.
Currently I'm spitting certain piece of info on logs and delimitting it using '|' character.
From Splunk search using regex_raw , eval and split i'm getting the desired data generated in columns.
I have added a report and scheduled it to send on necessary mail ID everyday using schedule -> actions in reporting.
However now the team wants the same report to be pushed on to a FTP server location. How can i acheive this ?