Splunk® Enterprise

Search Manual

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Export data using Splunk Web

1. Run a search on your data.

2. Click the export button, located directly below the timeline.

Splunk Export Button.jpg

Note: If the button is not visible, it has been hidden by your system administrator to preclude exporting data. For more information, see About defining roles with capabilities in the Securing Splunk Enterprise manual. Look for the export_results_is_visible capability.

3. Select the Format that you want the search results to be exported in. You can select CSV, Raw Events, XML or JSON.

4. Choose the Number of Results you want (Limited or Unlimited).

5. Click Export to confirm.

Extend the session timeout when exporting large amounts of data

When you try to export large amounts of data using the export button, you can run into session timeout issues. Follow this procedure to extend the session timeout limit.

1. Click Settings and select Server Settings.

2. Under Splunk Web, increase the number in the Session timeout field.

Timeout.png

Increasing the timeout settings allows Splunk Web more time for the connection between your browser and splunkweb.

Archive search results

If you need to archive your search results, you can export your job data to third-party charting applications. See Export job data to a file.

Schedule reports that send results to stakeholders

You can schedule reports to run on a regular interval and email their results to project stakeholders. The emails can present the report results in inline tables and CSV or PDF attachments. They can also include links to the report results in Splunk Web.

See Schedule Reports in the Reporting Manual.

PREVIOUS
Export search results overview
  NEXT
Export data using the CLI

This documentation applies to the following versions of Splunk® Enterprise: 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters