<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fix loss of text formatting in dashboard table field/column in simple xml in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/349287#M40653</link>
    <description>&lt;P&gt;You can open an &lt;CODE&gt;Enhancement Request&lt;/CODE&gt; as a P1 support case.&lt;/P&gt;</description>
    <pubDate>Sun, 06 Aug 2017 18:56:34 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2017-08-06T18:56:34Z</dc:date>
    <item>
      <title>fix loss of text formatting in dashboard table field/column in simple xml</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/349284#M40650</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;I find difficult to proper display relatively large text fields in dashboard tables - simple xml&lt;/P&gt;

&lt;P&gt;New lines are lost when displayed in dashboard table column, while being correct in the raw event.&lt;BR /&gt;
Data comes as XML, the field is CTRL_OUTPUT &lt;/P&gt;

&lt;P&gt;Below is some record content of column CTRL_OUTPUT as it shows on the Dashboard table:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;OMEGACAADM DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION NULL OMEGACATESTAPP01 DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION NULL OMEGACATESTDBA01 DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION NULL OMEGACATESTDEV01 DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION NULL OMEGACATESTDEV02 DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION NULL OMEGADBSCAN DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION NULL SYS DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION NULL TEST1 DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION NULL TEST2 DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION NULL TEST3 DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION NULL TEST4 DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION NULL TEST5 DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION NULL
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Below is the Raw event:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;SCAN_ID&amp;gt;20170714_210278_Ora_DB_T01_y&amp;lt;/SCAN_ID&amp;gt;&amp;lt;DB_NAME&amp;gt;Ora Test DB 01&amp;lt;/DB_NAME&amp;gt;&amp;lt;DB_HOST&amp;gt;db_test&amp;lt;/DB_HOST&amp;gt;&amp;lt;VLN_ID&amp;gt;10&amp;lt;/VLN_ID&amp;gt;&amp;lt;VLN_NAME&amp;gt;User Profile - Password Verify Function&amp;lt;/VLN_NAME&amp;gt;&amp;lt;SEVERITY_ID&amp;gt;2&amp;lt;/SEVERITY_ID&amp;gt;&amp;lt;SEVERITY_NAME&amp;gt;Medium&amp;lt;/SEVERITY_NAME&amp;gt;&amp;lt;CATEGORY_ID&amp;gt;0&amp;lt;/CATEGORY_ID&amp;gt;&amp;lt;CATEGORY_NAME&amp;gt;Authentication&amp;lt;/CATEGORY_NAME&amp;gt;&amp;lt;SCAN_CODE_ID&amp;gt;0&amp;lt;/SCAN_CODE_ID&amp;gt;&amp;lt;SCAN_CODE_NAME&amp;gt;Completed&amp;lt;/SCAN_CODE_NAME&amp;gt;&amp;lt;SCAN_MESSAGE&amp;gt;Completed&amp;lt;/SCAN_MESSAGE&amp;gt;&amp;lt;CTRL_FIND_ID&amp;gt;1&amp;lt;/CTRL_FIND_ID&amp;gt;&amp;lt;CTRL_FIND_NAME&amp;gt;Finding&amp;lt;/CTRL_FIND_NAME&amp;gt;&amp;lt;CTRL_SUMMARY&amp;gt;OMEGACAADM,OMEGACATESTAPP01,OMEGACATESTDBA01,OMEGACATESTDEV01,OMEGACATESTDEV02,OMEGADBSCAN,SYS,TEST1,TEST2,TEST3,TEST4,TEST5&amp;lt;/CTRL_SUMMARY&amp;gt;&amp;lt;CTRL_OUTPUT&amp;gt;OMEGACAADM
DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION
NULL
OMEGACATESTAPP01
DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION
NULL
OMEGACATESTDBA01
DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION
NULL
OMEGACATESTDEV01
DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION
NULL
OMEGACATESTDEV02
DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION
NULL
OMEGADBSCAN
DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION
NULL
SYS
DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION
NULL
TEST1
DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION
NULL
TEST2
DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION
NULL
TEST3
DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION
NULL
TEST4
DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION
NULL
TEST5
DEFAULT -&amp;gt; PASSWORD -&amp;gt; PASSWORD_VERIFY_FUNCTION
NULL
&amp;lt;/CTRL_OUTPUT&amp;gt;
Collapse
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;As it is seen above, the formatting (new lines) of the CTRL_OUTPUT is preserved in raw event, but it is lost in dashboard table display. &lt;BR /&gt;
Can this be fixed ?&lt;/P&gt;

&lt;P&gt;best regards&lt;BR /&gt;
Altin&lt;/P&gt;</description>
      <pubDate>Sat, 05 Aug 2017 18:29:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/349284#M40650</guid>
      <dc:creator>altink</dc:creator>
      <dc:date>2017-08-05T18:29:59Z</dc:date>
    </item>
    <item>
      <title>Re: fix loss of text formatting in dashboard table field/column in simple xml</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/349285#M40651</link>
      <description>&lt;P&gt;This is truly obnoxious default and inescapable behavior by Splunk: displaying newlines as spaces. I hate it. The &lt;EM&gt;ONLY&lt;/EM&gt; work-around it is to convert your field into a multi-valued field by adding this to the end:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makemv delim="
" CTRL_OUTPUT&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Feb 2024 22:32:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/349285#M40651</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2024-02-04T22:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: fix loss of text formatting in dashboard table field/column in simple xml</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/349286#M40652</link>
      <description>&lt;P&gt;Truly obnoxious.&lt;BR /&gt;
I wander how one can work this way with fields of kind memo/clob.&lt;/P&gt;

&lt;P&gt;I wish Splunk does something on this.&lt;/P&gt;

&lt;P&gt;Thank you very much Mr. woodcock&lt;/P&gt;</description>
      <pubDate>Sun, 06 Aug 2017 17:49:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/349286#M40652</guid>
      <dc:creator>altink</dc:creator>
      <dc:date>2017-08-06T17:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: fix loss of text formatting in dashboard table field/column in simple xml</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/349287#M40653</link>
      <description>&lt;P&gt;You can open an &lt;CODE&gt;Enhancement Request&lt;/CODE&gt; as a P1 support case.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Aug 2017 18:56:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/349287#M40653</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-08-06T18:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: fix loss of text formatting in dashboard table field/column in simple xml</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/349288#M40654</link>
      <description>&lt;P&gt;thank you Sir,&lt;/P&gt;

&lt;P&gt;but I guess I am not the first guy who wants to see a memo or clob field inside the table, long as it may be, but at least properly formatted.&lt;BR /&gt;&lt;BR /&gt;
I am not looking for a memo with scroll-bars popping on click per each record cell, built in dashboard table, &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;but if this is not done so far, I am not aiming so high,&lt;BR /&gt;
:-)&lt;/P&gt;

&lt;P&gt;thank you very much for helping me&lt;BR /&gt;
best regards&lt;BR /&gt;
Altin&lt;/P&gt;</description>
      <pubDate>Sun, 06 Aug 2017 20:55:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/349288#M40654</guid>
      <dc:creator>altink</dc:creator>
      <dc:date>2017-08-06T20:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: fix loss of text formatting in dashboard table field/column in simple xml</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/349289#M40655</link>
      <description>&lt;P&gt;I agree that the request is very reasonable but scroll-bars with a setting for #rows to show would be nice, too!&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2017 01:42:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/349289#M40655</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-08-07T01:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: fix loss of text formatting in dashboard table field/column in simple xml</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/349290#M40656</link>
      <description>&lt;P&gt;Hello Mr. woodcock&lt;/P&gt;

&lt;P&gt;I tried your command above but it didn't make any difference. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;     | makemv delim="
     " CTRL_OUTPUT
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However Splunk did recognize the presence of an Enter/New Line by some red highlighting.&lt;/P&gt;

&lt;P&gt;best regards&lt;BR /&gt;
Altin&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 19:48:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/349290#M40656</guid>
      <dc:creator>altink</dc:creator>
      <dc:date>2017-08-16T19:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: fix loss of text formatting in dashboard table field/column in simple xml</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/349291#M40657</link>
      <description>&lt;P&gt;I had the same issue when displaying vulnerability scan results (Nessus) in a dashboard table. The formatting looked weird.&lt;/P&gt;

&lt;P&gt;The accepted answer from @woodcock helped a little, but the formatting still looked weird: Multiple adjacent space characters are truncated to only one space character and paragraphs (two or more adjacent new lines) are truncated to one new line.&lt;/P&gt;

&lt;P&gt;I found another fix involving the CSS element "white-space: pre", &lt;A href="https://answers.splunk.com/answers/24889/table-wrap.html"&gt;similar to this question&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;First, I created the following css file in etc/apps/myapp/appserver/static/myapp-format.css&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#table1 .table td:nth-child(3) {
   white-space: pre !important;
}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will format the third column in the table. Next, I edited the dashboard XML as follows:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form stylesheet="myapp-format.css"&amp;gt;
...
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;    
      &amp;lt;table id="table1"&amp;gt;
...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I had to restart Splunk and clear the cache of my web browser for the changes to take effect.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 10:25:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/349291#M40657</guid>
      <dc:creator>Yunagi</dc:creator>
      <dc:date>2018-01-10T10:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: fix loss of text formatting in dashboard table field/column in simple xml</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/676510#M55393</link>
      <description>&lt;P&gt;WARNING!&amp;nbsp; &amp;nbsp;The new website is broken and cannot display newlines inside of double-quotes, even as a "code snippet" which is also moronic and inexcusable.&amp;nbsp; So while my correct answer looked fine and worked in the old answers site, the new one cannot be made to display a correct answer so I am going to DESSCRIBE IT.&amp;nbsp; The space that you see in the double-quotes is actually supposed to be a newline as in &amp;lt;"&amp;gt;&amp;lt;/n&amp;gt;&amp;lt;"&amp;gt;.&amp;nbsp; If you do that, it works.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Feb 2024 22:34:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/676510#M55393</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2024-02-04T22:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: fix loss of text formatting in dashboard table field/column in simple xml</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/676511#M55394</link>
      <description>&lt;P&gt;WARNING!&amp;nbsp; &amp;nbsp;The new website is broken and cannot display newlines inside of double-quotes, even as a "code snippet" which is also moronic and inexcusable.&amp;nbsp; So while my correct answer looked fine and worked in the old answers site, the new one cannot be made to display a correct answer so I am going to DESSCRIBE IT.&amp;nbsp; The space that you see in the double-quotes is actually supposed to be a newline as in &amp;lt;"&amp;gt;&amp;lt;/n&amp;gt;&amp;lt;"&amp;gt;.&amp;nbsp; If you do that, it works.&amp;nbsp; The stupid site is also forcing me to add an app, even this this Q/A has nothing to do with any app.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Feb 2024 22:37:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/fix-loss-of-text-formatting-in-dashboard-table-field-column-in/m-p/676511#M55394</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2024-02-04T22:37:10Z</dc:date>
    </item>
  </channel>
</rss>

