Splunk Search

Splunk CLI remote search parse _raw into fields

harishbajaj
Engager

I am using a locally installed Splunk instance to perform a remote search using the CLI.

splunk search "index=sandbox sourcetype=access http_status_code<400 earliest="10/01/2017:00:00:00" latest="10/02/2017:00:00:00"" -output csv -maxout 0 -max_time 0 -auth user:password -app remote_app -uri https://hostname:port > output.csv

"access" is a sourcetype that is defined on the remote Splunk enterprise server. When I get the results, how can I parse the _raw field into the individual fields that have field extractions defined on the remote Splunk server.

0 Karma
1 Solution

darrenfuller
Contributor

Try something like:

splunk search "index=sandbox sourcetype=access http_status_code<400 earliest="10/01/2017:00:00:00" latest="10/02/2017:00:00:00" | table _time, *, _raw" -output csv -maxout 0 -max_time 0 -auth user:password -app remote_app -uri https://hostname:port > output.csv

That way the remote Splunk sends you the timestamp, all the field date, plus the full _raw. Best of all words, and bonus: you don't need to use your local system resources to extract field data

View solution in original post

darrenfuller
Contributor

Try something like:

splunk search "index=sandbox sourcetype=access http_status_code<400 earliest="10/01/2017:00:00:00" latest="10/02/2017:00:00:00" | table _time, *, _raw" -output csv -maxout 0 -max_time 0 -auth user:password -app remote_app -uri https://hostname:port > output.csv

That way the remote Splunk sends you the timestamp, all the field date, plus the full _raw. Best of all words, and bonus: you don't need to use your local system resources to extract field data

harishbajaj
Engager

Thank you! That worked beautifully; exactly what I was looking for!

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...