Splunk Search

File not found on export

gmonroe
Explorer

When trying to export search results, I'm getting an error that reads "File not found. Firefox can't find the file at http...".

What would cause this and what are possible fixes for it?

Tags (1)

Moritz
Explorer

When you extend your searchstring with
| table _raw | outputcsv output.csv
you can find you exprted results in $SPLUNK_HOME/var/run/splunk.

0 Karma

reed_kelly
Contributor

We are havnig the same problem - even if Admin runs the same query. In fact, it seems to depend on how many rows are returned. If we return many rows, then the export returns this error more frequently. We have found that if we wait a minute or two, then we can click on the "Try Again" link in the message and it sometimes works. Also, if we cut and paste the link to the exported data, it starts to export. The queries that tend to do this also have many columns (80?).

We are running 4.3.1, build 119532 on our local search head in a globally distributed env.

0 Karma

DaveSavage
Builder

Sounds like access privileges? Are you running as admin or equiv, or has your user id sufficient permissions? If you have CLI access perhaps also check out the access controls in.../metadata filename is default.meta. Export may be set to Admin as the default.
Best wishes.
D

0 Karma

gmonroe
Explorer

We're searching an IP address. Searche results for other IP addresses can be exported, but for some reason this one shows the error. The data in the results events look fine.

We are on v. 4.3.3 in a distributed environment.

0 Karma

Drainy
Champion

Could you post the search? Also what version are you running? Is this a distributed environment?

0 Karma

gmonroe
Explorer

Dave, thanks for responding. I don't think it's a permissions issue. I, and other users, are able to export other search results, but this one in particular returns the error. In the meantime, I will do as you suggested and check the access controls and all permissions.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...