Splunk Enterprise Security

How to make a report or a CSV file from a search result?

ofaheem
New Member

Hi,

I want to make a report or a CSV file from a search result. However, the search result is more than 7 million. So now I have a few queries:

  • I am trying to save the search; however, whenever I try to open that search to show people how many and what type of events were found, it does not show.
  • How can I make a report or CSV file for more than 7 million events?

Please advise.

Thanks & regard,

Osama Faheem

Labels (1)
0 Karma

aasabatini
Motivator

Hi @ofaheem 

you can use outputlookup command in your search, there aren't limits.

Or you can follow this article

https://www.splunk.com/en_us/blog/tips-and-tricks/help-i-cant-export-more-than-10000-events.html?_ga...

 

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma
Get Updates on the Splunk Community!

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...