Reporting

Is it possible to export CSV results to network drive?

crsplunkr
Loves-to-Learn Everything

I have a request from one of our service managers about getting a inventory of all hosts logging into Splunk.

Using tstats does get the results we need via

| tstats values(host) by host

drilling down per index

| tstats values(host) as hosts where index=idxname by index

and exporting to a CSV file or emailing the results wont work for our current needs and he would like the exported CSV results to be stored on network drive on a weekly basis, or possibly some other format if that's an option.

Not sure if this is possible with the report actions currently available, as I only see webhook, emailing results etc. wondering if there is a way to do this with a addon alert action, or possibly another way?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @crsplunkr,

there are many questions like your in Community and the answer is always the same, you have two solutions:

the problem is that Splunk saves csv only in one fixed  folder ($SPLUNK_HOME/var/run/splunk/csv) and you have to move it using a scheduled shell script.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...