Splunk® Enterprise

Search Manual

Acrobat logo Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF

Export data using Splunk Web

1. Run a search on your data.

2. Click the export button, located directly below the timeline.

Splunk Export Button.jpg

Note: If the button is not visible, it has been hidden by your system administrator to preclude exporting data. For more information, see About defining roles with capabilities in the Securing Splunk Enterprise manual. Look for the export_results_is_visible capability.

3. Select the Format that you want the search results to be exported in. You can select CSV, Raw Events, XML or JSON.

4. Choose the Number of Results you want (Limited or Unlimited).

5. Click Export to confirm.

Extend the session timeout when exporting large amounts of data

When you try to export large amounts of data using the export button, you can run into session timeout issues. Follow this procedure to extend the session timeout limit.

1. Click Settings and select Server Settings.

2. Under Splunk Web, increase the number in the Session timeout field.


Increasing the timeout settings allows Splunk Web more time for the connection between your browser and splunkweb.

Archive search results

If you need to archive your search results, you can export your job data to third-party charting applications. See Export job data to a file.

Schedule reports that send results to stakeholders

You can schedule reports to run on a regular interval and email their results to project stakeholders. The emails can present the report results in inline tables and CSV or PDF attachments. They can also include links to the report results in Splunk Web.

See Schedule Reports in the Reporting Manual.

Last modified on 13 September, 2016
Export search results overview
Export data using the CLI

This documentation applies to the following versions of Splunk® Enterprise: 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters