Splunk Search

Why is there no Raw Events export option when I have a search with stats command or returns a table?

andrewkenth
Communicator

From the GUI, you should also see a "Raw Events" as an export option along with json, xml, and csv however I do not see Raw Events when I have a search that has the stats command present or returns a table. Any idea how to get a round this?

Tags (3)
0 Karma

andrewkenth
Communicator

That's what I thought was happening. I'd like to see what you see when you click on the events tab, the raw logs or a csv with each field in it. If Splunk can show you the related events why can't you export what you see?

0 Karma

somesoni2
Revered Legend

You will not see that option only for the searches with stats/table as there is no data present in event form. Since you've ran a stats/table command, what do you expect to see in the Raw Events export?

chris
Motivator

Stats is a transforming command you do not have any raw events anymore once you've used it.
http://docs.splunk.com/Splexicon:Transformingcommand

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...