Reporting

Is it possible to export CSV results to network drive?

crsplunkr
Loves-to-Learn Everything

I have a request from one of our service managers about getting a inventory of all hosts logging into Splunk.

Using tstats does get the results we need via

| tstats values(host) by host

drilling down per index

| tstats values(host) as hosts where index=idxname by index

and exporting to a CSV file or emailing the results wont work for our current needs and he would like the exported CSV results to be stored on network drive on a weekly basis, or possibly some other format if that's an option.

Not sure if this is possible with the report actions currently available, as I only see webhook, emailing results etc. wondering if there is a way to do this with a addon alert action, or possibly another way?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @crsplunkr,

there are many questions like your in Community and the answer is always the same, you have two solutions:

the problem is that Splunk saves csv only in one fixed  folder ($SPLUNK_HOME/var/run/splunk/csv) and you have to move it using a scheduled shell script.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...