Splunk Enterprise

How to send files from Splunk to SharePointOnline?

johnjohn
Engager

Hi All,

I need to automate the execution of specific queries in Splunk Enterprise on a weekly basis, export the results as CSV files, and upload them to a designated SharePoint Online folder for visualization purposes. Based on your experience, what are the available options, and which one would you recommend as the best?

 

Thanks,

John

Labels (1)
Tags (2)
0 Karma

johnjohn
Engager

Thank you Will, much appreciated.

John

livehybrid
SplunkTrust
SplunkTrust

Hi @johnjohn 

I know of 2 ways to achieve this, but there could be others.

  1. Enable incoming e-mail support for a list or library on Sharepoint - Check out https://support.microsoft.com/en-gb/office/enable-incoming-e-mail-support-for-a-list-or-library-dcaf... for more information on this. 
    You would then configure a scheduled search with an email alert action to send the CSV results to the email provided by Sharepoint and this would be added to the library.
  2. Use Microsoft Power Automate, as above you would use a scheduled search to send the CSV results.
    1. Create a Flow triggered by email:

      • Use the "When a new email arrives (V3)" trigger from Office 365 Outlook connector (This requires a O365/Outlook.com email account).
      • Add a condition to filter for emails with CSV attachments

    2. Configure the "Create file" action:

      • Connect to your SharePoint site
      • Select the destination library/folder
      • Choose to save the attachment from the email
      • Set dynamic content for the file name (keep original or create custom naming)

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...