Splunk Search

Link to a file in search results

srinisub
New Member

I have a zip file uploaded into Splunk. This zip file contains a files.csv file and some file attachments stored in files/ . Here's a sample record in files.csv.

File Id      File Name            File Path 
101704839   Ready_AHV.png       files/102231960.png

If I search for Ready_AHV.png, I get the above search result. What I am looking for is a link to the file path, so when I click on the link, it opens the file attachment. Let me know if there is a way to do this.

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

There's not a way to do this out of the box with Splunk. If you were to run Apache on the same box and put the files on a VirtualHost (in layman, that's Apache terminology for a website), then you could make the results look like this:

http://splunkserver:{VirtualHostPort}/path/to/file

And make that a hyperlink or drill down on a dashboard so that when the user clicks, it opens a new browser window and downloads the file.

View solution in original post

jkat54
SplunkTrust
SplunkTrust

There's not a way to do this out of the box with Splunk. If you were to run Apache on the same box and put the files on a VirtualHost (in layman, that's Apache terminology for a website), then you could make the results look like this:

http://splunkserver:{VirtualHostPort}/path/to/file

And make that a hyperlink or drill down on a dashboard so that when the user clicks, it opens a new browser window and downloads the file.

Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...