Reporting

How to export logs from Splunk with host, source and sourcetype fields

jackson_storm
Explorer

Hello. I have a questions.

How to export logs from Splunk Enterprise with "host", "source" and "sourcetype" fields ?
And how to import these logs into other Splunk Enterprise instance correctly ?

I'm trying to export Windows logs from my current Splunk instance and save it for future usage or upload into other Splunk.
Using "Export" button i can only export raw logs without necessary for me fields("host", "source" and "sourcetype")

Good example is ButterCup Games training logs in Splunk documentation. I need to get something like this.

splunker12er
Motivator

How to export logs from Splunk Enterprise with "host", "source" and "sourcetype" fields ?

<yoursearch> |  table host, source, sourcetype, _raw

Once results are displayed click export to download logs.

How to upload into other Splunk.? (I use CLI command)

splunk add monitor c:\xxxx.log -index yourindexname -source yoursourcename -sourcetype yoursourcetypename -hostname yourhostname
0 Karma

jackson_storm
Explorer

What format should i use ?
CSV, XML or JSON ?
Export as raw data is not supported

0 Karma
Get Updates on the Splunk Community!

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...