You can share a job with other Splunk users, or export the event data to archive or to use with a third-party charting application.
When you share a job, you are sharing the results of a specific run of a search.
There are several ways that you can share a specific job with other Splunk platform users. You can change the permissions for a search job to share that job with other users. You can also share a job by sending the URL for a search job to a Splunk platform user.
You can only change permissions or share a link to the current job.
Change job permissions
You can share a job by changing the permissions on that job. By default, all jobs are Private.
- From the Job menu, select Edit Job Settings to display the Job Settings dialog box.
- Change Read Permissions to Everyone.
- Click Save
You can share a job with other Splunk users by sending them a link to the job. This is handy when you want another user to see the results returned by the job.
The users that you send the link to must have permissions to use the app that the job belongs to.
Decide which method you want to use to obtain a job link. You can use the Share icon or the Job menu.
- To use the Share icon:
- Click the icon. The Share icon is one of the search action icons.
- In the Link To Job text box, copy the URL and send the link to the users that you want to share the job results with.
The permissions on the job are automatically changed to Everyone and the lifetime of the job is automatically extended to 7 days.
- To use the Job menu:
- From the Job menu, select Edit Job Settings to display the Job Settings dialog box.
- Change Read Permissions to Everyone. If the permissions for a job are set to Private, other users cannot access the job with the link.
- Change Lifetime to 7 days.
- Copy the link and send the link to the users you want to share the job results with.
You can also save the link for your own use by using the Bookmark icon. The Bookmark icon appears in both the Job Settings dialog box and the Share Jobs dialog box. You can click and drag the Bookmark icon to the bookmarks bar in your Web browser.
Export job results to a file
You can export your job results in a variety of format such as CSV, JSON, PDF, Raw Events, and XML. You can then archive the file, or use the file with a third-party charting application. The format options depend on the type of job artifact that you are working with.
- If the search generates calculated data that appears on the Statistics tab, you cannot export using the Raw Events format.
- If the search is a saved search, such as a Report, you can export using the PDF format.
The export file is saved in the default download directory for your browser or operating system.
There are several methods that you can use to export search results. A few of these methods include Splunk Web, CLI, SDKs, and REST. Some of the methods are optimized for speed, while others are good for extremely large event sets.
For a complete list of the export methods and links to the specific steps, see Export search results.
Extending job lifetimes | Manage search jobs |
This documentation applies to the following versions of Splunk® Enterprise: 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 7.2.10, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10, 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.1.8, 8.1.9, 8.1.10, 8.1.11, 8.1.12, 8.1.13, 8.1.14, 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.2.7, 8.2.8, 8.2.9, 8.2.10, 8.2.11, 8.2.12, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.0.10
Feedback submitted, thanks!