Knowledge Management

How to post "events data file.csv" from Splunk to sharepoint.

mohan401
Engager

I am searching events form data summary with meaningful search patterns. Now I need to post my results into share point link with CSV file format. I am using SPLUNK version 6 in Windows platform, How can I post my results into share point? I have to install any plug-in for this?

0 Karma
1 Solution

sbbadri
Motivator

Have your scheduled search run an "exportcsv"/outputlookup command in the end and the exported csv file will be created in $SPLUNK_HOME/var/run/splunk folder. Later configure an scripted input to either push directly to sharepoint (using some API) or copy it to sharepoint's shared location.

View solution in original post

0 Karma

deepika
Loves-to-Learn

@mohan401  I have similar use case. I am very new to written scripts. Could you please share the scripts that you have written.

0 Karma

sbbadri
Motivator

Have your scheduled search run an "exportcsv"/outputlookup command in the end and the exported csv file will be created in $SPLUNK_HOME/var/run/splunk folder. Later configure an scripted input to either push directly to sharepoint (using some API) or copy it to sharepoint's shared location.

0 Karma

mohan401
Engager

I am connecting SPLUNK through web interface(UI) and I have only User and Dev permissions on my hand. Where I will get $SPLUNK_HOME/var/run/splunk folder.

0 Karma

sbbadri
Motivator

okay. You can use outputlookup command in your search query and save as report from GUI. so that it will save your report in corresponding apps folder. Then use scripted inputs to post that data in sharepoint.

Below is the link for outputloookup command,

http://docs.splunk.com/Documentation/SplunkCloud/6.5.1/SearchReference/Outputlookup

0 Karma

mohan401
Engager

I have created csv file using output lookup, then I have installed "splunk app for unix" but I didn't get where to write script. I have searched a lot, we need to change in config file?

0 Karma

sbbadri
Motivator

click on settings->Data Inputs->Scripts.

Scripth Path-> $SPLUNK_HOME$/etc/apps/splunk_app_for_unix/bin
Command -> your command or steps
Interval Inputs -> seconds
Interval ->
Source name override : optional

0 Karma

mohan401
Engager

Thank you sbbadri, In Command block we can only select the script which one we have to run but I want to know how to copy my script into $SPLUNK_HOME$/etc/apps/splunk_app_for_unix/bin path

0 Karma

mohan401
Engager

And one more thing actually I don't have Data Inputs option in settings. How to enable it?

0 Karma

sbbadri
Motivator

Then you don't have enough permission. So need to ask the right person to copy the scripts to $SPLUNK_HOME/etc/apps/splunk_app_for_unix through ssh to that server.

0 Karma

sbbadri
Motivator

For Data Inputs option you need to modify your role i.e., need to add right capabilities.

Below is the link,
https://docs.splunk.com/Documentation/Splunk/6.6.2/Admin/Authorizeconf

0 Karma

mohan401
Engager

Can you know where Dashboards will save and how to copy to SharePoint link

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...