<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom event viewer for records that have XML, JSON in addition to other data in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Custom-event-viewer-for-records-that-have-XML-JSON-in-addition/m-p/177601#M186760</link>
    <description>&lt;P&gt;"Beginning with version 6.0, Splunk Enterprise does not support the customization of event displays using event renderers"&lt;BR /&gt;
:(&lt;/P&gt;</description>
    <pubDate>Wed, 22 Oct 2014 12:45:20 GMT</pubDate>
    <dc:creator>Rocket66</dc:creator>
    <dc:date>2014-10-22T12:45:20Z</dc:date>
    <item>
      <title>Custom event viewer for records that have XML, JSON in addition to other data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Custom-event-viewer-for-records-that-have-XML-JSON-in-addition/m-p/177599#M186758</link>
      <description>&lt;P&gt;I've got a large number of logs which look similar to:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;INFO  com.this.that.SomeLogger 2014-05-08 08:29:49,997 [CSP-12.3.4.3245432] [pool-10-thread-1] {"metaData":{"sourceURI":"/search/" ....}}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;INFO  com.this.that.SomeLogger 2014-05-08 08:29:49,997 [CSP-12.3.4.3245432] [pool-10-thread-1] payload=&amp;lt;event type="x12"&amp;gt;...&amp;lt;/event&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;in addition to log entries with a freeform text or name-value pair load.&lt;/P&gt;

&lt;P&gt;It the whole event was JSON then Splunk would format this nicely in the event viewer panel but this doesn't work for the above mixed entries. Changing the logs to all JSON is at present not an option.&lt;/P&gt;

&lt;P&gt;One way seems to be creating custom events viewers that would deal with displaying above mixed events so users awkwardly end up copy-pasting payload into a JSON or XML formatter. &lt;BR /&gt;
I hope it's possible to improve presentation of events with mixed content with limited effort, e.g. by facilitating an already existing Splunk app or deriving custom events viewers from existing ones.&lt;/P&gt;

&lt;P&gt;What are my options?&lt;/P&gt;</description>
      <pubDate>Sat, 24 May 2014 15:37:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Custom-event-viewer-for-records-that-have-XML-JSON-in-addition/m-p/177599#M186758</guid>
      <dc:creator>tpflicke</dc:creator>
      <dc:date>2014-05-24T15:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: Custom event viewer for records that have XML, JSON in addition to other data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Custom-event-viewer-for-records-that-have-XML-JSON-in-addition/m-p/177600#M186759</link>
      <description>&lt;P&gt;Have you looked at a custom event renderers? &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.1/AdvancedDev/EventRendering"&gt;http://docs.splunk.com/Documentation/Splunk/6.0.1/AdvancedDev/EventRendering&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 24 May 2014 23:33:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Custom-event-viewer-for-records-that-have-XML-JSON-in-addition/m-p/177600#M186759</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2014-05-24T23:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: Custom event viewer for records that have XML, JSON in addition to other data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Custom-event-viewer-for-records-that-have-XML-JSON-in-addition/m-p/177601#M186760</link>
      <description>&lt;P&gt;"Beginning with version 6.0, Splunk Enterprise does not support the customization of event displays using event renderers"&lt;BR /&gt;
:(&lt;/P&gt;</description>
      <pubDate>Wed, 22 Oct 2014 12:45:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Custom-event-viewer-for-records-that-have-XML-JSON-in-addition/m-p/177601#M186760</guid>
      <dc:creator>Rocket66</dc:creator>
      <dc:date>2014-10-22T12:45:20Z</dc:date>
    </item>
  </channel>
</rss>

