Reporting

OUTPUTCSV file extension "csv" not applied to one of my searches.

r999
Path Finder

This seems strange, I have 2 searches which produce a simple table of results. i have added the following to the end of the saved search.

| outputcsv "metrics/metrics_data1_feed"
| outputcsv "metrics/metrics_data2_feed"

However, one of the reports does not add the file extension ".csv"

Files create:

/apps/splunk/var/run/splunk/metrics/metrics_data1_feed
/apps/splunk/var/run/splunk/metrics/metrics_data2_feed.csv

What is going on?

Do I just need to change command to
| outputcsv "metrics/metrics_data1_feed.csv"
| outputcsv "metrics/metrics_data2_feed.csv"

Tags (1)
0 Karma

iamthecat32
New Member

Does anyone have an answer to this?

I also am having this same problem. From what I can tell the extension is being written depending on the number of results sent to the csv file. The larger the number of results, the more likely you won't have the .csv extension.

Can someone confirm this, discuss a work-around?

😞

0 Karma

cedarcrestone
Explorer

I am experiencing this same issue and trying to figure it out as well. What is the max number of events that can be written to a csv file?

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...