Reporting

best way to export logfiles

a212830
Champion

Hi,

I have some customers who want to take their logfiles and export them, so that they can then be imported into another tool. The files are pretty large, and the exports are taking a while (as is the download). Is there another way to export the files? A way to pipe them (in raw format) to another directory?

Tags (1)
0 Karma

strive
Influencer

Then in that case it has to be incremental searches.

0 Karma

grijhwani
Motivator

If your only problem is one of export capacity and this is an ongoing requirement, perhaps you could use a scheduled search to export in time-stamped incremental chunks over specified time ranges?

0 Karma

strive
Influencer

Agree it has to be incremental searches

0 Karma

a212830
Champion

The customer doesn't have access to the logs, hence the need for Splunk.

0 Karma

strive
Influencer

From the source (host) itself why dont you send logs to 3rd Party tool as well your Splunk forwarder.

0 Karma

a212830
Champion

The tool is 3rd party tool that the developers use to do some analysis. We only want -_raw. It's very app specific. Currently, they run the search, and then export the file, which can be very large. I've seen it crash the splunk gui once already.

0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

You might want to give a bit more detail. When you say "export"... what are you doing now? What is this other tool? Does this other tool make use of anything except _raw?

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...