I'm trying to export, dump, or download large quantity of data from splunk. So far I tried dump command and the splunk cli search command to do this
-When I ran the search in the UI followed by the dump command and once the search finished I was unable to locate the file. Place I look for was /opt/splunk/var/run/splunk/dispatch, but I may be looking in the wrong system...is it my indexer or searchhead where this file is located?
-using the cli search command created some memory issues or login failures
Note:I am the Splunk Admin, 6 indexer, 6 searchheads