Hi, I have created a saved search and scheduled it to run weekly basis.
Any pointers on how to export the results in a csv and send it to sharepoint location.
You could write an alert script that connects to sharepoint and sends the results, and have that script triggered by your weekly scheduled report.
Agree with @martin_mueller. Have your scheduled search run an "exportcsv" command in the end and the exported csv file will be created in $SPLUNK_HOME/var/run/splunk folder. Later configure an alert executing script to either push directly to sharepoint (using some API) or copy it to sharepoint's shared location.