Splunk Search

extract code

ryosefi
New Member

Once I have filter the data I need using search App I wish to extract the code (Java or python or other) for future use. is it possible?

Tags (1)
0 Karma

lguinn2
Legend

When you run a search, you can download your output. There is an icon beneath the search box that has a down-arrow; this is the Export button. Click it, choose "Raw Events" and name the file. It will be created on your client machine (PC, laptop, whatever).
It will be a simple text file and you can then do whatever you want to it.

0 Karma

ryosefi
New Member

thanks 🙂 .

0 Karma

lguinn2
Legend

Yes, but what do you mean by "extract"? This word has a particular meaning in Splunk.

Do you want to output the code to a file? Do you want to create a report, etc?

0 Karma

ryosefi
New Member

Yes I wish to output the code to a file.

0 Karma

ryosefi
New Member

I wish to output the code and to be able to run it by itself on a laptop that has no splunk installed

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...