Splunk Search
Highlighted

How can I export the events that are the result of a search?

Communicator

How can I export the results of a search? I run a search and I get 922 events. I would like to export (or produce a report) of those results. However, when I try to build a report, I just get the count of the events - not the events themselves? I have tried searching the manual and the knowledge base without success.

Thanks.

Tags (3)
Highlighted

Re: How can I export the events that are the result of a search?

Builder

Can you give an example of the search you are using?

0 Karma
Highlighted

Re: How can I export the events that are the result of a search?

Splunk Employee
Splunk Employee

Multiple choices here Steve, from your search dashboard you can:
- Actions:Save results - for later viewing through Jobs manager page
- Actions:Export results - for exporting to .csv or other available formats
- Actions:Build report... - to build a report of the data. By default the report gets created as | timechourt count if you would like something different, then click on "Define Data using search language"
- Actions:Save search - if you want this to be an automated search. You can have it send you an email alert as well as a csv/pdf of the results.

More on the above in the Users Manual pages..