Splunk Search

Why is there no Raw Events export option when I have a search with stats command or returns a table?

andrewkenth
Communicator

From the GUI, you should also see a "Raw Events" as an export option along with json, xml, and csv however I do not see Raw Events when I have a search that has the stats command present or returns a table. Any idea how to get a round this?

Tags (3)
0 Karma

andrewkenth
Communicator

That's what I thought was happening. I'd like to see what you see when you click on the events tab, the raw logs or a csv with each field in it. If Splunk can show you the related events why can't you export what you see?

0 Karma

somesoni2
Revered Legend

You will not see that option only for the searches with stats/table as there is no data present in event form. Since you've ran a stats/table command, what do you expect to see in the Raw Events export?

chris
Motivator

Stats is a transforming command you do not have any raw events anymore once you've used it.
http://docs.splunk.com/Splexicon:Transformingcommand

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...