Splunk Search

Why is there no Raw Events export option when I have a search with stats command or returns a table?

andrewkenth
Communicator

From the GUI, you should also see a "Raw Events" as an export option along with json, xml, and csv however I do not see Raw Events when I have a search that has the stats command present or returns a table. Any idea how to get a round this?

Tags (3)
0 Karma

andrewkenth
Communicator

That's what I thought was happening. I'd like to see what you see when you click on the events tab, the raw logs or a csv with each field in it. If Splunk can show you the related events why can't you export what you see?

0 Karma

somesoni2
SplunkTrust
SplunkTrust

You will not see that option only for the searches with stats/table as there is no data present in event form. Since you've ran a stats/table command, what do you expect to see in the Raw Events export?

chris
Motivator

Stats is a transforming command you do not have any raw events anymore once you've used it.
http://docs.splunk.com/Splexicon:Transformingcommand

Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...