Splunk® Enterprise

Search Manual

Download manual as PDF

Download topic as PDF

Share jobs and export results

You can share a job with other Splunk users, or export the event data to archive or to use with a third-party charting application.

Share a job with others

When you share a job, you are sharing the results of a specific run of a search.

There are several ways that you can share a specific job with other Splunk users. You can change the permissions for a search job to share that job with other users. You can also share a job by sending the URL for a search job to a Splunk user.

You can only change permissions or share a link to the current job.

Change job permissions

You can share a job by changing the permissions on that job. By default, all jobs are "Private".

  1. From the Job menu, select Edit Job Settings to display the Job Settings dialog box.
  2. Change Read Permissions to Everyone.
  3. Click Save.
This screen image shows the Job Settings dialog box.

Share a job URL

You can quickly share a job with other Splunk users by sending them a link to the job. This is handy when you want another user to see the results returned by the job.

The users that you send the link to should also have permissions to use the app that the job belongs to.

Decide which method you want to use to obtain a job link. You can use the Share icon or the Job menu.

  1. To use the Share icon:
    1. Click the icon. The Share icon is one of the search action icons.
    2. In the Link To Job text box, copy the URL and send the link to the users you want to share the job results with.
    The permissions on the job are automatically changed to "Everyone" and the lifetime of the job is automatically extended to "7 days".
    This screen image shows the Share Jobs dialog box and the Share icon. The Share icon is a curved arrow pointing to the right.
  2. To use the Job menu:
    1. From the Job menu, select Edit Job Settings to display the Job Settings dialog box.
    2. Change Read Permissions to Everyone. If the permissions for a job are set to "Private", other users cannot access the job with the link.
    3. Change Lifetime to 7 days.
    4. Copy the link and send the link to the users you want to share the job results with.
6.4 job settings dialog.png

You can also save the link for your own use. Click and drag the bookmarks icon to the bookmarks bar in your Web browser.

Export job results to a file

You can export your job results in a variety of format such as CSV, JSON, PDF, Raw Events, and XML. You can then archive the file, or use the file with a third-party charting application. The format options depend on the type of job artifact that you are working with.

  • If the search generates calculated data that appears on the Statistics tab, you cannot export using the Raw Events format.
  • If the search is a saved search, such as a Report, you can export using the PDF format.


The export file is saved in the default download directory for your browser or operating system.

There are several methods that you can use to export search results. A few of these methods include Splunk Web, CLI, SDKs, and REST. Some of the methods are optimized for speed, while others are good for extremely large event sets.

For a complete list of the export methods and links to the specific steps, see Export search results.

PREVIOUS
Extending job lifetimes
  NEXT
Manage search jobs

This documentation applies to the following versions of Splunk® Enterprise: 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 7.0.0, 7.0.1


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters