Reporting

Is it possible to export CSV results to network drive?

crsplunkr
Loves-to-Learn Everything

I have a request from one of our service managers about getting a inventory of all hosts logging into Splunk.

Using tstats does get the results we need via

| tstats values(host) by host

drilling down per index

| tstats values(host) as hosts where index=idxname by index

and exporting to a CSV file or emailing the results wont work for our current needs and he would like the exported CSV results to be stored on network drive on a weekly basis, or possibly some other format if that's an option.

Not sure if this is possible with the report actions currently available, as I only see webhook, emailing results etc. wondering if there is a way to do this with a addon alert action, or possibly another way?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @crsplunkr,

there are many questions like your in Community and the answer is always the same, you have two solutions:

the problem is that Splunk saves csv only in one fixed  folder ($SPLUNK_HOME/var/run/splunk/csv) and you have to move it using a scheduled shell script.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...