instead of /var/run/splunk? I would like to stay away from having to point to or move the file in a script.
There is not. You can create a script that is triggered after the search is done and the outputcsv has written the file and explicitly put it into a Splunk bin
folder to do this, but you probably knew that.
Part of the reason is security related, to prevent search users from being able to have Splunk create files in arbitary locations.
There is not. You can create a script that is triggered after the search is done and the outputcsv has written the file and explicitly put it into a Splunk bin
folder to do this, but you probably knew that.
Part of the reason is security related, to prevent search users from being able to have Splunk create files in arbitary locations.