Splunk Enterprise

How to send files from Splunk to SharePointOnline?

johnjohn
Engager

Hi All,

I need to automate the execution of specific queries in Splunk Enterprise on a weekly basis, export the results as CSV files, and upload them to a designated SharePoint Online folder for visualization purposes. Based on your experience, what are the available options, and which one would you recommend as the best?

 

Thanks,

John

Labels (1)
Tags (2)
0 Karma

johnjohn
Engager

Thank you Will, much appreciated.

John

livehybrid
SplunkTrust
SplunkTrust

Hi @johnjohn 

I know of 2 ways to achieve this, but there could be others.

  1. Enable incoming e-mail support for a list or library on Sharepoint - Check out https://support.microsoft.com/en-gb/office/enable-incoming-e-mail-support-for-a-list-or-library-dcaf... for more information on this. 
    You would then configure a scheduled search with an email alert action to send the CSV results to the email provided by Sharepoint and this would be added to the library.
  2. Use Microsoft Power Automate, as above you would use a scheduled search to send the CSV results.
    1. Create a Flow triggered by email:

      • Use the "When a new email arrives (V3)" trigger from Office 365 Outlook connector (This requires a O365/Outlook.com email account).
      • Add a condition to filter for emails with CSV attachments

    2. Configure the "Create file" action:

      • Connect to your SharePoint site
      • Select the destination library/folder
      • Choose to save the attachment from the email
      • Set dynamic content for the file name (keep original or create custom naming)

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...