Getting Data In

After using outputcsv in a Splunk search, where is this CSV file located?

asarran
Path Finder

Hey Splunkers

I'm new to Splunk and I'm having issues attempting to export a search results to a CSV file.

<MY SEARCH> | outputcsv  mycsvfilename

The trouble I'm having is the ability to locate the CSV file on my desktop. I can't find the file. The assumption is that the file is being sent somewhere else? I'm curious if anyone has ever encountered a problem similar to this before.

Thank You,

Tags (3)
0 Karma
1 Solution

Raghav2384
Motivator

Hello @asarran,

Please take a look : https://docs.splunk.com/Documentation/Splunk/6.4.2/SearchReference/Outputcsv

If you have Splunk Enterprise, this command saves search results to the specified CSV file on the local search-head in the $SPLUNK_HOME/var/run/splunk/csv directory. Updates to $SPLUNK_HOME/var/run/*.csv using the outputcsv command are not replicated across the cluster.

You can then add that csv back as a lookup or monitoring that directory for *.csv if outputcsv is something you use very often. Hope this helps

Hope this Helps!

Thanks,
Raghav

View solution in original post

Raghav2384
Motivator

Hello @asarran,

Please take a look : https://docs.splunk.com/Documentation/Splunk/6.4.2/SearchReference/Outputcsv

If you have Splunk Enterprise, this command saves search results to the specified CSV file on the local search-head in the $SPLUNK_HOME/var/run/splunk/csv directory. Updates to $SPLUNK_HOME/var/run/*.csv using the outputcsv command are not replicated across the cluster.

You can then add that csv back as a lookup or monitoring that directory for *.csv if outputcsv is something you use very often. Hope this helps

Hope this Helps!

Thanks,
Raghav

asarran
Path Finder

interesting, unfortunately I currently don't have access to the command interface of the header. I'm wandering would there be any other means I can export this query to a csv file on my desktop. I believe one option would be to schedule a report and have the report be emailed. I'm curious is there another method that is available?

Thanks, Raghav

0 Karma

somesoni2
Revered Legend

You should be able to export the search result manually (if running the search on ad-hoc basis). See this

http://docs.splunk.com/Documentation/Splunk/6.4.2/Search/Exportsearchresults#Export_data_using_Splun...

asarran
Path Finder

Thank You.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...