Hi All,
We have observed whenever we are exporting search results in .csv format in the results alternative rows will be blank. We have checked for multiple log types but for all the exported logs alternative rows are blank.
Splunk vesrion 6.3.1
Please suggest
Hi All,
we have installed fresh setup of 6.6.5 in our test environment and post which we have run the searches, but again we have faced same issue of alternative rows blank.
In meantime we have observed whenever searches are rerunning while exporting we use to get the alternative rows blank in the result, If search didn’t rerun we use to get the export properly
he search is rerun when the search head believes that it cannot retrieve all of the events from the job artifact. The search head determines when to rerun the search based on the following logic:
• If the search is not a report, and one of the following is true.
• The search is not done
• The search is using a remote timeline
• The search head believes that the search has not retained all of events