Splunk Search

Showing events in a raw web browser window ? literally have a very basic raw events vizualization

guilmxm
Influencer

Hi,

I have a strong request from my client that wants to be to be able to view events resulting from a SPL search in a very very basic We browser window.

Literally, what they want is the same kind of visualization you would get with any web server accessing an ASCII log file... None of built in visualizations for events (event, table) really answers to what they want.

Within Splunk, this is like showing the raw file with the "show_source" interface or the job inspector and the search.log hyperlink.

Does anyone knows a possibility to get this to work within a Splunk view ? I was thinking in creating a search manager within an html module, but after i don't know how to send the flow to a basic html window...

alt text

alt text

Thank you in advance 🙂

0 Karma

elliotproebstel
Champion

Here's the closest solution I know:

Make a dashboard that contains exactly one panel - a statistics table. The search for that table should be: your search | table _raw

In the visualizations settings, you can expand the number of visible rows to 100. I believe that's the greatest number of rows you can display at once; the rest will paginate.

0 Karma

elliotproebstel
Champion

@guilmxm - Did this work for you?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...