Reporting

outputcsv: can I tell it where to create the CSV

davesplunkmonky
Splunk Employee
Splunk Employee

instead of /var/run/splunk? I would like to stay away from having to point to or move the file in a script.

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

There is not. You can create a script that is triggered after the search is done and the outputcsv has written the file and explicitly put it into a Splunk bin folder to do this, but you probably knew that.

Part of the reason is security related, to prevent search users from being able to have Splunk create files in arbitary locations.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

There is not. You can create a script that is triggered after the search is done and the outputcsv has written the file and explicitly put it into a Splunk bin folder to do this, but you probably knew that.

Part of the reason is security related, to prevent search users from being able to have Splunk create files in arbitary locations.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...