Assuming not SHC, create a
cron job in the OS of the Search Head that runs every X-minutes looking in the
dispatch directory for files named
XFERME_<destination>_<real_name_starts_here>.csv which does
rm. Create them using
sorry couldnt get this.
Currently I'm spitting certain piece of info on logs and delimitting it using '|' character.
From Splunk search using regex_raw , eval and split i'm getting the desired data generated in columns.
I have added a report and scheduled it to send on necessary mail ID everyday using schedule -> actions in reporting.
However now the team wants the same report to be pushed on to a FTP server location. How can i acheive this ?
One option is to create your custom alert action (Ref https://docs.splunk.com/Documentation/Splunk/8.0.0/AdvancedDev/ModAlertsIntro) to achieve this, in this option you need to write script.
Other option is, this add-on https://splunkbase.splunk.com/app/4398/ might work but I never tried this add-on.