Splunk Enterprise

Splunk Times out on large Data Export of Table

itsmevic
Communicator

Hello, Splunk is timing out after I try and use the export feature in UI.  There is quite a bit of data that needs to be exported.  Is there a way to keep it from timing out?

Labels (1)
0 Karma

The_Simko
Path Finder

This is where the session timeout field comes into play. Settings > Server Settings > General Settings.  Then in the Splunk Web section change the Session Timeout.

Now, if that still doesn't work you always have some options like using |outputlookup to write the data as a .csv and then pick it up. Obviously it only works for certain types of data, and requires you to be able to access the CLI to get a copy of the data, but it may work for some uses.

Another thing to try would be use to REST API to export, like shown in this post from Discovered Intelligence: https://discoveredintelligence.ca/get-data-out-of-splunk/#:~:text=A%20user%20can%20call%20the,on%2Dp...

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...