You can share a job with other Splunk users, or export the event data to archive or to use with a third-party charting application.
When you share a job, you are sharing the results of a specific run of a search.
There are several ways that you can share a specific job with other Splunk users. You can change the permissions for a search job to share that job with other users. You can also share a job by sending the URL for a search job to a Splunk user.
You can only change permissions or share a link to the current job.
Change job permissions
You can share a job by changing the permissions on that job. By default, all jobs are "Private".
- From the Job menu, select Edit Job Settings to display the Job Settings dialog box.</li>
- Change Read Permissions to Everyone.</li>
- Click Save.
You can quickly share a job with other Splunk users by sending them a link to the job. This is handy when you want another user to see the results returned by the job.
The users that you send the link to should also have permissions to use the app that the job belongs to.
Decide which method you want to use to obtain a job link. You can use the Share icon or the Job menu.
- To use the Share icon:
- Click the icon. The Share icon is one of the search action icons.
- In the Link To Job text box, copy the URL and send the link to the users you want to share the job results with.
- From the Job menu, select Edit Job Settings to display the Job Settings dialog box.
- Change Read Permissions to Everyone. If the permissions for a job are set to "Private", other users cannot access the job with the link.
- Change Lifetime to 7 days.
- Copy the link and send the link to the users you want to share the job results with.
You can also save the link for your own use. Click and drag the bookmarks icon to the bookmarks bar in your Web browser.
Export job results to a file
You can export your job results in a variety of format such as CSV, JSON, PDF, Raw Events, and XML. You can then archive the file, or use the file with a third-party charting application. The format options depend on the type of job artifact that you are working with.
- If the search generates calculated data that appears on the Statistics tab, you cannot export using the Raw Events format.
- If the search is a saved search, such as a Report, you can export using the PDF format.
The export file is saved in the default download directory for your browser or operating system.
There are several methods that you can use to export search results. A few of these methods include Splunk Web, CLI, SDKs, and REST. Some of the methods are optimized for speed, while others are good for extremely large event sets.
For a complete list of the export methods and links to the specific steps, see Export search results.
Extending job lifetimes
Manage search jobs
This documentation applies to the following versions of Splunk® Enterprise: 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 6.6.9, 6.6.10, 6.6.11, 6.6.12, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8