Splunk Search

Why is there no Raw Events export option when I have a search with stats command or returns a table?

andrewkenth
Communicator

From the GUI, you should also see a "Raw Events" as an export option along with json, xml, and csv however I do not see Raw Events when I have a search that has the stats command present or returns a table. Any idea how to get a round this?

Tags (3)
0 Karma

andrewkenth
Communicator

That's what I thought was happening. I'd like to see what you see when you click on the events tab, the raw logs or a csv with each field in it. If Splunk can show you the related events why can't you export what you see?

0 Karma

somesoni2
Revered Legend

You will not see that option only for the searches with stats/table as there is no data present in event form. Since you've ran a stats/table command, what do you expect to see in the Raw Events export?

chris
Motivator

Stats is a transforming command you do not have any raw events anymore once you've used it.
http://docs.splunk.com/Splexicon:Transformingcommand

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...