index=DMZWEBTEST POST "/checkout/giftcard/balance" |stats count as giftcard_balanceCount by Source_ip|where giftcard_balanceCount>=18|fields - giftcard_balanceCount|outputlookup IP.csv
This is the query and I need to place this .csv file at C OR D drive path. Please help.
I've been playing around with this one and I haven't found a way to override it. I did find this topic
The idea to create a file mover would be the easiest solution.
Yeah, pretty sure you can't do this from Splunk.