Hi all,
I currently have 1 search head running all my scheduled searches. Some of these searches use the outputcsv
command to export Splunk results for use in other systems. Will these CSV files be replicated by the search head cluster? I won't be able to control which search head produces the CSV, so I need to know if Splunk deals with this or not.
I've searched through the documentation, but haven't found anything explicit. Any help would be greatly appreciated!
Thanks
http://docs.splunk.com/Documentation/Splunk/6.4.1/SearchReference/Outputcsv
Updates to $SPLUNK_HOME/var/run/*.csv using the outputcsv command are not replicated across the cluster.
This answered my question
outputlookup
is better because
- As woodcock said, it is replicated to all SH members in a SHC
- You can control where the csv resides. Example if your app has a saved-search, it will ensure that the csv will reside within the app and NOT in $SPLUNK_HOME/var/run/ , thus providing more acl to the lookup
http://docs.splunk.com/Documentation/Splunk/6.4.1/SearchReference/Outputcsv
Updates to $SPLUNK_HOME/var/run/*.csv using the outputcsv command are not replicated across the cluster.
This answered my question
You can switch from outputcsv
to outputlookup
and use a KV Store
instead and that should replicate everywhere.
Thanks Gregg, this is probably the best workaround we were able to come up with