Splunk Search

extract code

ryosefi
New Member

Once I have filter the data I need using search App I wish to extract the code (Java or python or other) for future use. is it possible?

Tags (1)
0 Karma

lguinn2
Legend

When you run a search, you can download your output. There is an icon beneath the search box that has a down-arrow; this is the Export button. Click it, choose "Raw Events" and name the file. It will be created on your client machine (PC, laptop, whatever).
It will be a simple text file and you can then do whatever you want to it.

0 Karma

ryosefi
New Member

thanks 🙂 .

0 Karma

lguinn2
Legend

Yes, but what do you mean by "extract"? This word has a particular meaning in Splunk.

Do you want to output the code to a file? Do you want to create a report, etc?

0 Karma

ryosefi
New Member

Yes I wish to output the code to a file.

0 Karma

ryosefi
New Member

I wish to output the code and to be able to run it by itself on a laptop that has no splunk installed

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...