Splunk Search

How to export raw events instead of statistics?

Woodpecker
Path Finder

Hi,

I have a query which gives a table of results. Now instead of exporting the table, I need to export the raw events itself. How can I do that?

Instead of exporting 9980 values, I need to export the whole 16882 events

Any help would be appreciated!

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

When you click the Export icon, choose "Raw events" from the Format dropdown.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Woodpecker
Path Finder

I want to enable a email alert action and export the results as raw events

0 Karma

richgalloway
SplunkTrust
SplunkTrust

That's an option in the alert action.

richgalloway_0-1679316603353.png

 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...