Related to this question:
When I run:
search * | head 10 | /home/splunk/test/aaa.csv
I see this error:
Could not write to file '/home/splunk/test/aaa.csv
More info:
Anyone have any idea what this could be?
Outputcsv will only write files to splunk's var/run/splunk directory, for security reasons. It will not write to arbitrary file system locations. You could, I believe, create a symlink (or hard link) to a directory under there and write to that location however.
Outputcsv will only write files to splunk's var/run/splunk directory, for security reasons. It will not write to arbitrary file system locations. You could, I believe, create a symlink (or hard link) to a directory under there and write to that location however.
Have you created the csv lookup file under
manager -> lookups -> lookup table files -> new ?
Also, I think your syntax is wrong, and what you actually want to type is
search * |head 10| outputcsv csvfilename.csv
csvfilename.csv being the name of the file you created in the first step.
See if that works for you.
Indeed, I meant to have outputcsv there.
outputcsv doesn't require a lookup table to be created though. I think you're thinking of outputlookup.
It works if I give it a relative path like "filename.csv", but not an absolute path. I'm trying to automate delivery of reports to a shared drive.