Splunk Search

Link to a file in search results

srinisub
New Member

I have a zip file uploaded into Splunk. This zip file contains a files.csv file and some file attachments stored in files/ . Here's a sample record in files.csv.

File Id      File Name            File Path 
101704839   Ready_AHV.png       files/102231960.png

If I search for Ready_AHV.png, I get the above search result. What I am looking for is a link to the file path, so when I click on the link, it opens the file attachment. Let me know if there is a way to do this.

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

There's not a way to do this out of the box with Splunk. If you were to run Apache on the same box and put the files on a VirtualHost (in layman, that's Apache terminology for a website), then you could make the results look like this:

http://splunkserver:{VirtualHostPort}/path/to/file

And make that a hyperlink or drill down on a dashboard so that when the user clicks, it opens a new browser window and downloads the file.

View solution in original post

jkat54
SplunkTrust
SplunkTrust

There's not a way to do this out of the box with Splunk. If you were to run Apache on the same box and put the files on a VirtualHost (in layman, that's Apache terminology for a website), then you could make the results look like this:

http://splunkserver:{VirtualHostPort}/path/to/file

And make that a hyperlink or drill down on a dashboard so that when the user clicks, it opens a new browser window and downloads the file.

Get Updates on the Splunk Community!

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...

Enterprise Security Content Update (ESCU) | New Releases

In October, the Splunk Threat Research Team had one release of new security content via the Enterprise ...