Splunk Search

Why is there no Raw Events export option when I have a search with stats command or returns a table?

andrewkenth
Communicator

From the GUI, you should also see a "Raw Events" as an export option along with json, xml, and csv however I do not see Raw Events when I have a search that has the stats command present or returns a table. Any idea how to get a round this?

Tags (3)
0 Karma

andrewkenth
Communicator

That's what I thought was happening. I'd like to see what you see when you click on the events tab, the raw logs or a csv with each field in it. If Splunk can show you the related events why can't you export what you see?

0 Karma

somesoni2
Revered Legend

You will not see that option only for the searches with stats/table as there is no data present in event form. Since you've ran a stats/table command, what do you expect to see in the Raw Events export?

chris
Motivator

Stats is a transforming command you do not have any raw events anymore once you've used it.
http://docs.splunk.com/Splexicon:Transformingcommand

Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...