Reporting

OUTPUTCSV file extension "csv" not applied to one of my searches.

r999
Path Finder

This seems strange, I have 2 searches which produce a simple table of results. i have added the following to the end of the saved search.

| outputcsv "metrics/metrics_data1_feed"
| outputcsv "metrics/metrics_data2_feed"

However, one of the reports does not add the file extension ".csv"

Files create:

/apps/splunk/var/run/splunk/metrics/metrics_data1_feed
/apps/splunk/var/run/splunk/metrics/metrics_data2_feed.csv

What is going on?

Do I just need to change command to
| outputcsv "metrics/metrics_data1_feed.csv"
| outputcsv "metrics/metrics_data2_feed.csv"

Tags (1)
0 Karma

iamthecat32
New Member

Does anyone have an answer to this?

I also am having this same problem. From what I can tell the extension is being written depending on the number of results sent to the csv file. The larger the number of results, the more likely you won't have the .csv extension.

Can someone confirm this, discuss a work-around?

😞

0 Karma

cedarcrestone
Explorer

I am experiencing this same issue and trying to figure it out as well. What is the max number of events that can be written to a csv file?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...