Is it possible to extend the export capabilities from splunk, in order to export to other formats :
- export all _raw events to zip format
- export xml fields to zip file with xml files...
Is it possible to write some function that the standard ui can use ?
The dump
command looks like it might do a lot of what you want:
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Dump
Yes it is very close, thank you... but I'm missing a way to get the data via ui or rest, without having to access the server directly