Reporting

outputcsv: can I tell it where to create the CSV

davesplunkmonky
Splunk Employee
Splunk Employee

instead of /var/run/splunk? I would like to stay away from having to point to or move the file in a script.

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

There is not. You can create a script that is triggered after the search is done and the outputcsv has written the file and explicitly put it into a Splunk bin folder to do this, but you probably knew that.

Part of the reason is security related, to prevent search users from being able to have Splunk create files in arbitary locations.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

There is not. You can create a script that is triggered after the search is done and the outputcsv has written the file and explicitly put it into a Splunk bin folder to do this, but you probably knew that.

Part of the reason is security related, to prevent search users from being able to have Splunk create files in arbitary locations.

Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 3)

Welcome back to Splunk Classroom Chronicles, our ongoing blog series that pulls back the curtain on Splunk ...

Operationalizing TDIR: Building a More Resilient, Scalable SOC

Optimizing SOC workflows with a unified, risk-based approach to Threat Detection, Investigation, and Response ...

Almost Too Eventful Assurance: Part 1

Modern IT and Network teams still struggle with too many alerts and isolating issues before they are notified. ...