I'm using this method to run a search and export the results to a CSV:
http://docs.splunk.com/Documentation/Splunk/latest/Search/Exportsearchresults#Export_using_the_Splunk_Enterprise_REST_API
The fields which are available on the GUI through search time field extractions with INDEXED_EXTRACTIONS = CSV do not appear in the CSV fetched from the REST API.
How can I achieve that?
↧