Splunk Search

File not found on export

gmonroe
Explorer

When trying to export search results, I'm getting an error that reads "File not found. Firefox can't find the file at http...".

What would cause this and what are possible fixes for it?

Tags (1)

Moritz
Explorer

When you extend your searchstring with
| table _raw | outputcsv output.csv
you can find you exprted results in $SPLUNK_HOME/var/run/splunk.

0 Karma

reed_kelly
Contributor

We are havnig the same problem - even if Admin runs the same query. In fact, it seems to depend on how many rows are returned. If we return many rows, then the export returns this error more frequently. We have found that if we wait a minute or two, then we can click on the "Try Again" link in the message and it sometimes works. Also, if we cut and paste the link to the exported data, it starts to export. The queries that tend to do this also have many columns (80?).

We are running 4.3.1, build 119532 on our local search head in a globally distributed env.

0 Karma

DaveSavage
Builder

Sounds like access privileges? Are you running as admin or equiv, or has your user id sufficient permissions? If you have CLI access perhaps also check out the access controls in.../metadata filename is default.meta. Export may be set to Admin as the default.
Best wishes.
D

0 Karma

gmonroe
Explorer

We're searching an IP address. Searche results for other IP addresses can be exported, but for some reason this one shows the error. The data in the results events look fine.

We are on v. 4.3.3 in a distributed environment.

0 Karma

Drainy
Champion

Could you post the search? Also what version are you running? Is this a distributed environment?

0 Karma

gmonroe
Explorer

Dave, thanks for responding. I don't think it's a permissions issue. I, and other users, are able to export other search results, but this one in particular returns the error. In the meantime, I will do as you suggested and check the access controls and all permissions.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...