Splunk Search

How can I export the events that are the result of a search?

steveirogers
Communicator

How can I export the results of a search? I run a search and I get 922 events. I would like to export (or produce a report) of those results. However, when I try to build a report, I just get the count of the events - not the events themselves? I have tried searching the manual and the knowledge base without success.

Thanks.

Tags (3)

Genti
Splunk Employee
Splunk Employee

Multiple choices here Steve, from your search dashboard you can:
- Actions:Save results - for later viewing through Jobs manager page
- Actions:Export results - for exporting to .csv or other available formats
- Actions:Build report... - to build a report of the data. By default the report gets created as | timechourt count if you would like something different, then click on "Define Data using search language"
- Actions:Save search - if you want this to be an automated search. You can have it send you an email alert as well as a csv/pdf of the results.

More on the above in the Users Manual pages..

Brian_Osburn
Builder

Can you give an example of the search you are using?

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...